2018-11-27 | DOF 5544804Added
The National Banking and Securities Commission modifies the general provisions applicable to credit institutions to strengthen the regulatory framework for information security and technological infrastructure. The resolution introduces new definitions for information security incidents and sensitive user information, mandates specific internal controls for authentication and operational contingency, and establishes a new section on information security requiring institutions to implement a control system ensuring the confidentiality, integrity, and availability of their technological infrastructure. It also updates reporting obligations for operational contingencies and replaces specific annexes regarding biometric data capture and security indicators.
If the document is presented incomplete on the right margin, it is because it contains tables that exceed the default width. If this is the case, click here to view it correctly.
DOF: 27/11/2018
RESOLUTION modifying the general provisions applicable to credit institutions
A seal with the National Coat of Arms, which reads: United Mexican States.- Ministry of Finance and Public Credit.- National Banking and Securities Commission, is placed at the margin.
The National Banking and Securities Commission, based on the provisions of articles 52, eighth paragraph, and 96 Bis of the Credit Institutions Law, as well as 4, fractions XXXVI and XXXVIII; 16, fraction I, and 19 of the National Banking and Securities Commission Law, and
CONSIDERING
That in accordance with article 78 of the General Law for Regulatory Improvement and with the aim of reducing the compliance cost of these provisions, the National Banking and Securities Commission, through a resolution published in the Official Gazette of the Federation on June 26, 2017, reformed the "Resolutor modifying the General Provisions applicable to credit institutions" published in the same medium on January 6, 2017, with the objective of extending the deadline that credit institutions have to have 100% of the amount of preventive estimates for credit risks corresponding to non-revolving consumer credit portfolios, housing mortgages, and microcredits constituted, in accordance with the use of the new applicable methodology, while clarifying when this information must be disclosed in their financial statements, as well as in any public communication of financial information, and
That in order to be able to face risks and cyberattacks that could cause damage to credit institutions and to the execution of operations with clients, it is convenient to strengthen the regulatory framework on the security of their systems and technological infrastructures, as well as to reinforce the internal controls they must have, establishing a regime that seeks to guarantee the security of the technological infrastructure on which their operations are supported and the confidentiality, integrity, and availability of information, so that they have specific measures, tending to protect their information, certainty in their operation, and continuity of services, has resolved to issue the following:
RESOLUTION MODIFYING THE GENERAL PROVISIONS APPLICABLE TO
CREDIT INSTITUTIONS
SOLE.- Articles 1, fractions XIII, XXXIX, and current fraction LXXXI; 11, first paragraph; 12, fraction III; 15 Bis, fraction V, first paragraph; 51 Bis 3, fraction I and last paragraph; 51 Bis 5, fraction I; 51 Bis 9, fraction I; 86, fraction III, subsection b), numerals 1 to 3; 141, fraction III; 160, fraction III; 164, fraction IV, subsections f) and h); 164 Bis, fraction III; 166, fraction III; 169, first paragraph, 315 Bis, fraction I, and 316 Bis 14, first paragraph; are REFORMED; Articles 1, fractions LXXVI, LXXXIII, CXXXVI, and CXCII, with the remaining fractions being renumbered in order and as appropriate; 160, fraction XIV; Title Two, Chapter VI, Section Eighth Bis to be named "On Information Security" which comprises articles 168 Bis 11 to 168 Bis 17; 316 Bis 10, fraction V, as well as Annexes 64 Bis and 72; are ADDED; Articles 15 Bis, fraction V, subsections a) to e); 71, fraction IX; 86, fraction III, subsection b), numeral 3, subsections i. to vi.; 164, fraction V; 166, fraction V; 316 Bis 12; 316 Bis 17, and 316 Bis 20; are REPEALED; and Annexes 64 and 71 of the "General Provisions applicable to credit institutions", published in the Official Gazette of the Federation on December 2, 2005, and modified through resolutions published in the said Official Gazette on March 3 and 28, September 15, December 6 and 8, 2006; January 12, March 23, April 26, and November 5, 2007; March 10, August 22, September 19, October 14, and December 4, 2008; April 27, May 28, June 11, August 12, October 16, November 9, and December 1 and 24, 2009; January 27, February 10, April 9 and 15, May 17, June 28, July 29, August 19, September 9 and 28, October 25, November 26, and December 20, 2010; January 24 and 27, March 4, April 21, July 5, August 3 and 12, September 30, October 5 and 27, and December 28, 2011; June 19, July 5, October 23, November 28, and December 13, 2012; January 31, April 16, May 3, June 3 and 24, July 12, October 2, and December 24, 2013; January 7 and 31, March 26, May 12 and 19, July 3 and 31, September 24, October 30, December 8 and 31, 2014; January 9, February 5, April 30, May 27, June 23, August 27, September 21, October 29, November 9 and 13, December 16 and 31, 2015; April 7 and 28, June 22, July 7 and 29, August 1, September 19 and 28, and December 27, 2016; January 6, April 4 and 27, May 31, June 26, July 4 and 24, August 29, October 6 and 25, December 18, 26, and 27, 2017; January 22, March 14, April 26, May 11, June 26, July 23, August 29, and November 15, 2018, to remain as follows:
TITLES FIRST and FIRST BIS
...
TITLE TWO
...
Chapters I to V
...
Chapter VI
...
Sections First to Eighth
...
Section Eighth Bis
On Information Security
Section Ninth
...
Chapters VII to IX
...
TITLES SECOND to FIFTH ...
Annexes 1 to 63
...
Annex 64
Incidents affecting information security.
Annex 64 Bis
Report on Information Security Incidents.
Annexes 65 to 70
...
Annex 71
Technical requirements for the capture of fingerprints and facial identification as biometric data.
Annex 72
Information security indicators.
" Article 1.-
...
I. to XII.
...
XIII.
Authentication: the set of techniques and procedures used to verify the identity of:
a)
A User and their authority to perform operations through the Electronic Banking service, or a User of the Technological Infrastructure to access, use, or operate any component of the Technological Infrastructure.
b)
An Institution and its authority to receive instructions through the Electronic Banking service.
XIV. to XXXVIII.
...
XXXIX.
Operational Contingency: any event that hinders, limits, or prevents an Institution from providing its services or carrying out those processes that could have an impact on the Public User.
XL. to LXXV.
...
LXXVI.
Information Security Incident: an event that the Institution evaluates according to its management processes, which may:
a)
Endanger the confidentiality, integrity, or availability of a component or the entirety of the Technological Infrastructure used by an Institution or of the information that said infrastructure processes, stores, or transmits.
b)
Represent a loss, extraction, alteration, or misplacement of information.
c)
Constitute a violation of information security policies and procedures.
d)
Represent the materialization of a loss due to damage, interruption, alteration, or failures derived from the use of hardware, software, systems, applications, networks, and any other channel of information transmission in the provision of services, in Technological Infrastructures interconnected that allow interactions between people, processes, data, and components of information and telecommunications technologies, and which are caused or derive, among others, in unauthorized access, misuse of information or systems, fraud, theft of information, or in interruption of services, which puts at risk the confidentiality, integrity, and availability of information.
e)
Vulnerate the systems or components of the Technological Infrastructure with an adverse effect on the Institution, its clients, third parties, suppliers, or counterparties, commonly known as cyber-attacks.
LXXVII. to LXXXI.
...
LXXXII.
Sensitive Information or User Sensitive Information: information of the Public User, which contains names, addresses, phone numbers, or email addresses, or any other data that identifies said persons together with bank card numbers, account numbers, credit limits, balances, amounts, and other data of a financial nature, as well as User Identifiers or Authentication information.
LXXXIII.
Technological Infrastructure: computer equipment, data processing and communications facilities, communications equipment and networks, operating systems, databases, applications, and systems that Institutions use to support their operation.
LXXXIV. to CXXXV.
...
CXXXVI.
Security Master Plan: the document that establishes the security strategy of an Institution to ensure proper management of information security and avoid the materialization of Information Security Incidents that could negatively affect the Institution.
CXXXVII to CLIV.
...
CLV. to CXCI.
...
CXCII.
User of the Technological Infrastructure: the person, User, or physical or logical component that accesses, uses, or operates the Technological Infrastructure of the Institutions.
CXCIII. to CXCVII
... "
" Article 11.- Institutions in the development of Credit Activity, must have for each of the stages, processes, adequate personnel, and Technological Infrastructure that allow the achievement of their objectives in credit matters, adhering to these provisions, as well as to the methodologies, models, policies, and procedures established in their credit manual.
...
Article 12.-
...
I. and II.
...
III.
Maintain adequate controls that guarantee the confidentiality, integrity, and availability of information that ensure their security both physically and logically, as well as measures for the recovery of information in cases of Operational Contingency, in terms of Articles 164 Bis and 168 Bis 11 of these provisions.
IV.
... "
" Article 15 Bis.-
...
I. to IV.
...
V.
Maintain the confidentiality, integrity, and availability of information observing, in the case of systems managed by Institutions, the controls indicated in Article 168 Bis 11, as well as measures in cases of Operational Contingency in terms of Article 164 Bis of these provisions.
a) to e) Are repealed.
...
... "
" Article 51 Bis 3.-
...
I.
The detailed description of the mechanism, which must be approved by its Board of Directors, as well as of the Technological Infrastructure used in each part of the process.
II.
...
In any case, in the implementation of the approved mechanism for the formation of the fingerprint database, Institutions must first capture the fingerprints of their employees, executives, or officials who will be in charge of collecting those of clients, and subsequently collect those of their clients. Likewise, they must observe what is stated in the second and third paragraphs of section I of Annex 71 of these provisions " .
" Article 51 Bis 5 .- . . .
...
I.
The detailed description of the process, which must be approved by its Board of Directors, as well as the Technological Infrastructure used in each part of this.
II. and III.
...
... "
" Article 51 Bis 9.- . . .
I.
The detailed description of the process, which must be approved by the Board of Directors, as well as the Technological Infrastructure used in each part of this.
II. to VII.
...
... "
" Article 71.- . . .
I. to VIII.
...
IX.
Approve the methodology for classifying vulnerabilities in information security according to their criticality, probability of occurrence, and impact.
... "
" Article 86 .-
.
.
I. and II.
...
III.
...
a)
...
b)
...
Comply with what is established in Section Eighth Bis of Chapter VI of Title Two of these provisions.
Establish controls for the identification and resolution of those acts or events that could generate risks for the Institution derived from:
i.
The commission of fraudulent facts, acts, or operations through technological means.
ii.
The inadequate use by Users of the Technological Infrastructure.
Establish and implement policies and procedures for the classification of information and its treatment, according to the risk that the security of the information is violated determined by each of the Business Units and other operational areas of the Institution. This classification must be included in the manuals for Integrated Risk Management referred to in the last paragraph of Article 78 of these provisions and be used to evaluate and implement the necessary controls in the Technological Infrastructure and in operational processes, in order to preserve the confidentiality, integrity, and availability of the Institution's and its clients' information.
i. to vi.
Are repealed.
The Institution must evaluate situations that in terms of technological risk could affect its ordinary operation, which must be monitored permanently in order to verify the performance of the Integrated Risk Management process.
c)
...
... "
" Article 141 .- . . .
I. and II.
...
III.
Those that regulate and control matters related to the Technological Infrastructure, including automated data processing systems and telecommunications networks referred to in Article 52 of the Law.
IV.
... "
" Article 160 .- . . .
...
I. and II.
...
III.
Verify that the Technological Infrastructure that supports the operation and internal processes of the Institution, including accounting systems, credit portfolio operational systems, securities, or any other type, have mechanisms to preserve the integrity, confidentiality, and availability of information, that prevent its alteration and comply with the objectives for which they were implemented or designed, in terms of Article 168 Bis 11 of these provisions. Likewise, periodically monitor the Technological Infrastructure in order to identify potential failures and verify that it generates sufficient, consistent information and that it flows adequately.
...
IV. to XIII.
...
XIV.
Evaluate based on the annual work program referred to in fraction XI of this article, the management process of Information Security Incidents referred to in Article 168 Bis 14 of these provisions.
Penultimate paragraph. - Repealed.
... "
" Article 164.-
...
...
...
I. to III.
...
IV.
...
a) to e)
...
f)
Protect the integrity and proper maintenance of the Technological Infrastructure, including automated data processing systems and telecommunications networks referred to in Article 52 of the Law, as well as the integrity, confidentiality, and availability of information received, generated, processed, stored, and transmitted by these, in terms of Article 168 Bis 11 of these provisions. Additionally, procedures must be established so that clients can report the theft or loss of any of their Authentication Factors, even when Institutions operate through their agents.
g)
...
h)
Ensure that information security procedures, organizational structures, and policies are observed in accordance with the Institution.
i)
...
V.
Is repealed.
VI. to IX.
...
...
...
Article 164 Bis .- . . .
...
I. and II.
...
III.
Inform the Commission of Operational Contingencies, by email sent to contingencias@cnbv.gob.mx, or through other means that the Commission itself makes available, an electronic receipt must be generated, always when these interruptions have a duration of at least sixty minutes and update any of the following circumstances:
a)
When failures occur in the Technological Infrastructure that supports the services of Branches and Electronic Banking.
b)
When they generate an impact on the critical components of the Technological Infrastructure that has resulted in the total or partial activation of the Business Continuity Plan.
c)
When they generate an impact of 30% in their Branches; ATMs; Point of Sale Terminals or points of attention of their agents for scenarios different from impacts in the Technological Infrastructure, to which Annex 67 of these provisions refers.
The aforementioned notification must be made within sixty minutes following the update of any of the aforementioned criteria, and must include the date and time of the start of the Operational Contingency; the indication of whether it continues or, if applicable, if it has concluded and its duration; the affected processes, systems, and channels; a description of the event that has been registered, and an initial evaluation of the impact or gravity. The Institution must communicate daily to the Commission, through the means indicated in the first paragraph of this fraction, the status of the Operational Contingency until such time as it is concluded, and, regarding the last communication, must include the date and time when it is determined that it has concluded and its total duration.
Likewise, the general manager must send to the Commission, within a period not exceeding 15 business days following the conclusion of the Operational Contingency, an analysis of the causes that motivated it, the impact caused in qualitative and quantitative terms that includes, at least, the temporality, the monetary impact breaking down the detail of costs, and the indication of the actions that will be implemented to minimize damage in similar subsequent situations, including the work plan that is elaborated for this purpose, which must contain at least the personnel responsible for its design, implementation, execution, and monitoring, deadlines for its execution, detail of activities performed and to be performed, as well as the technical, material, and human resources employed.
... "
" Article 166 .- . . .
I. and II.
...
III.
Promote the correct functioning of the Technological Infrastructure in accordance with the security measures referred to in Article 168 Bis 11 of these provisions, assisting for such effect with the chief information security officer referred to in Article 168 Bis 14 of these provisions, as well as the elaboration of complete, correct, precise, integral, reliable, and timely information, including that which must be provided to competent authorities, and which contributes to adequate decision-making.
IV.
...
V.
Is repealed.
Last paragraph.- Repealed.
" Section Eighth Bis
On Information Security
Article 168 Bis 11.- The general manager of the Institution will be responsible for the implementation of the Internal Control System in matters of information security that ensures its confidentiality, integrity, and availability. The management framework referred to in this paragraph must ensure that the Technological Infrastructure, whether owned or provided by third parties, adheres to the following requirements:
I.
That each of its components performs the functions for which it was designed, developed, or acquired.
II.
That its processes, functionalities, and configurations, including its development or acquisition methodology, as well as the record of its changes, updates, and the detailed inventory of each component of the Technological Infrastructure, are documented.
III.
That information security aspects have been considered in the definition of projects to acquire or develop each of its components, including them during the various stages of the lifecycle. This will comprise the elaboration of requirements, design, development or acquisition, implementation testing, acceptance testing by Users of the Technological Infrastructure, release processes including vulnerability testing and code analysis prior to production, periodic testing, change management, replacement, and destruction of information.
In the case of communications and computing components, security aspects must include, at least, the following:
a)
Logical segregation, or logical and physical segregation of different networks in different domains and subnets, depending on the function they perform or the type of data transmitted, including segregation of production environments from development and testing environments, as well as perimeter and network security components that ensure that only authorized traffic is permitted. In particular, in those segments with links to the outside, such as the Internet, providers, authorities, other networks of the Institution or headquarters, and other third parties, all of this referred to critical services, whether payment systems, encryption equipment, operation authorizers, among others, consider safe zones, including those known as demilitarized zones (DMZ).
b)
Secure configuration according to the type of component, considering at least, ports and services, permissions granted under the principle of least privilege, use of removable storage media, access lists, manufacturer updates, and reconfiguration of factory parameters. The principle of least privilege will be understood as the enabling of access only to the information and resources necessary for the development of the functions of each User of the Technological Infrastructure.
IV.
That each of its components is tested before being implemented or modified, using quality control mechanisms that prevent the use of real data from the production environment, the disclosure of confidential or security information, or the introduction of any functionality not recognized for said component.
V.
That it has the licenses or use authorizations, if applicable.
VI.
That it has security measures for its protection, as well as for the access and use of the information that is received, generated, transmitted, stored, and processed in the own Technological Infrastructure, having at least the following:
a)
Identification and Authentication mechanisms for all and each of the Users of the Technological Infrastructure, which allow them to be recognized unequivocally and ensure access only to persons expressly authorized for this purpose, under the principle of least privilege.
For the foregoing, relevant controls must be included for those Users of the Technological Infrastructure with greater privileges, derived from their functions, such as those for database and operating system administration.
Likewise, policies and procedures must be provided for access authorizations by exception, such as users of development environments with access to production environments and access due to contingency events, among others. Such policies and procedures must be approved by the Chief Information Security Officer.
b)
Encryption of information according to the degree of sensitivity or classification that the Institution determines and establishes in its policies, when such information is transmitted, exchanged, and communicated between components, or stored in the Technological Infrastructure or accessed remotely.
c)
Access keys with composition characteristics that prevent unauthorized access, considering processes that ensure that only the User of the Technological Infrastructure knows them, as well as security measures, encryption in storage, and mechanisms to change access keys every 90 days or less. In the case of Users of the Technological Infrastructure assigned to applications or components to authenticate with each other, the change referred to in this subsection must be carried out at least once a year. In the event that any User of the Technological Infrastructure has knowledge of the access keys and ceases to provide their services to the Institution, these must be modified immediately.
d)
Controls to automatically terminate unattended sessions, as well as to prevent unauthorized simultaneous sessions with the same User of the Technological Infrastructure identifier.
e)
Security mechanisms, both physical access and environmental and electrical energy controls, that protect the Technological Infrastructure and allow operation in accordance with the specifications of the provider, manufacturer, or developer.
f)
Validation measures to guarantee the authenticity of transactions executed by the different components of the Technological Infrastructure, considering, at least, the following:
The truthfulness and integrity of the information.
Authentication between components of the Technological Infrastructure, which ensure that only legitimate service requests are executed from their origin to their execution and registration.
Messaging, communication, and encryption protocols, which must ensure the integrity and confidentiality of the information.
The identification of atypical transactions, anticipating that applications will have automatic alert measures for attention by the corresponding operational areas.
The update and maintenance of digital certificates and components provided by service providers that are integrated into the transaction execution process.
The measures referred to in this subsection must be established in accordance with the degree of risk that the Institutions define for each type of transaction.
VII.
That it have backup mechanisms and information recovery procedures that mitigate the risk of operational interruption, in accordance with what is provided in Article 164 Bis of these provisions.
VIII.
That it maintain complete audit records, including detailed information of accesses or access attempts and the operation or activity carried out by Users of the Technological Infrastructure, this, regardless of the level of privileges they have for access, generation, or modification of the information they receive, generate, store, or transmit in each component of the Technological Infrastructure, including automated process activity, as well as procedures for the periodic review of such records.
Institutions must conserve the audit records referred to in this subsection for a period of three years when such records refer to activities carried out on components that process or store information considered as critical in accordance with the classification indicated in Article 86, subsection III, subsection b), numeral 3 of these provisions. Otherwise, the conservation period of the records will be a minimum of six months.
IX.
That for the attention of Information Security Incidents, there be management processes that ensure detection, classification, attention, and containment, investigation, and, if applicable, digital forensic analysis, diagnosis, reporting to competent hierarchical levels, solution, follow-up, and communication to authorities, clients, and counterparties of such incidents.
For the detection and response to Information Security Incidents referred to in the previous paragraph, the General Director must designate a team that incorporates personnel from the different areas of the Institution to participate in each activity of the management process mentioned above, of which, in any case, the Chief Information Security Officer must be a part in accordance with subsection VII of Article 168 Bis 14 of these provisions.
In the event that vulnerabilities and deficiencies in the Technological Infrastructure are detected, corrective actions or compensatory controls must be taken according to the level of risk involved, preventing Users of the Technological Infrastructure or the Institution from being affected.
X.
That it be subjected to annual planning and review exercises that allow measuring its capacity to support its operation, guaranteeing that the detected capacity increase needs resulting from such exercises are attended to promptly.
Likewise, the Institution must evaluate the obsolescence of the components of the Technological Infrastructure, having a plan for their update.
XI.
That it have automated controls or, in their absence, compensatory controls, such as double verification, which prior to or subsequent to the operation in question, minimize the risk of elimination, exposure, alteration, or modification of information, derived from manual or semi-automated processes carried out by the Institution's personnel, with the objective of preventing errors, omissions, theft, or manipulation of information.
XII.
That it have controls that allow detecting the alteration or forgery of books, records, and digital documents related to the active, passive, and service operations of the Institution.
XIII.
That it have processes to measure and ensure availability levels and response times, which guarantee the execution of operations and services performed; this including scenarios where Institutions contract the provision of services by external providers for the processing and storage of information.
XIV.
That it have automated devices or mechanisms to detect and prevent events and Information Security Incidents, as well as to prevent unauthorized incoming or outgoing data connections and flows and information leakage, considering among others, removable storage media.
Institutions must correlate the data obtained from the automated devices or mechanisms referred to in the previous paragraph with data from other sources, such as activity records or Information Security Incidents.
Additionally, to what is stated in the previous paragraph, Institutions must maintain controls that prevent the leakage of information corresponding to the configuration of the Technological Infrastructure, such as IP addresses, firewall rules, as well as hardware and software versions.
XV.
That for the provision of information technology services to Users of the Technological Infrastructure, in their strategy, design, transition, operation, and continuous improvement phases, the integrity of the Technological Infrastructure as well as the integrity, confidentiality, and availability of the information received, generated, processed, stored, and transmitted by it be protected.
The General Director will be responsible for documenting in policies and procedures what is provided for in this article.
Article 168 Bis 12.- The General Director of the Institution will be responsible for compliance with the following obligations regarding the Technological Infrastructure:
I.
Approve the Security Master Plan, which must be aligned with the Institution's business strategy, as well as define and prioritize projects in the matter of information security, with the objective of reducing exposure to technological risks and the materialization of Information Security Incidents up to acceptable levels in the terms defined by the Board, based on an analysis of the current situation.
For the approval of said plan, the General Director must verify that it contains initiatives directed at improving existing work methods and may contemplate the required controls in accordance with applicable provisions.
The General Director must inform the Board of the content of the Security Master Plan, and have evidence of its implementation.
II.
Carry out security reviews, focused on verifying the sufficiency of controls applicable to the Technological Infrastructure. These reviews must comprise at least the following:
a)
Authentication Mechanisms of Users of the Technological Infrastructure.
b)
Configuration and access controls to the Technological Infrastructure.
c)
Updates required for operating systems and software in general, prior to their implementation and once implemented.
d)
Identification of possible unauthorized modifications to the original software.
e)
Devices, communication networks, systems, and processes associated with Electronic Means and public attention channels, in order to verify that there are no vulnerabilities or that there are tools or procedures that allow knowing the Authentication Credentials of Users of the Technological Infrastructure, as well as any information that directly or indirectly could give access to the Technological Infrastructure on behalf of the User of the Technological Infrastructure.
The reviews referred to in this subsection must be carried out, at least, once a year or before if significant changes occur in the Technological Infrastructure. To determine if it is a significant change, the opinion of the Chief Information Security Officer must be obtained for this purpose.
III.
Elaborate an annual calendar for the performance of vulnerability scanning tests of the components of the Technological Infrastructure that store, process, or transmit information, prioritizing them according to the result of the information classification exercise referred to in Article 86, subsection III, subsection b), numeral 3. The calendar must provide for the quarterly review of some of the components of the Technological Infrastructure so that by the end of the year, all components that store, process, or transmit information classified as critical have been reviewed, as well as those that the Institution considers necessary. The General Director will be responsible for monitoring that such tests are carried out either through the Institution itself or a third party hired for this purpose. Additionally, when new components of the Technological Infrastructure are incorporated, the General Director will be responsible for monitoring that the vulnerability scanning test is performed prior to their production deployment.
IV.
Hire an independent third party, with personnel who have verifiable technical capacity through specialized industry certifications in the matter, for the performance of penetration tests in the different systems and applications of the Institution with the purpose of detecting errors, vulnerabilities, unauthorized functionality, or any code that puts or may put at risk the information and assets of clients and the Institution itself. Such review must include the verification of the integrity of hardware and software components that allow detecting alterations to them. Such tests must consider, at least, the following:
a)
Their scope and methodology, which must be validated by the Chief Information Security Officer.
b)
To be carried out at least twice a year on different systems and applications, or when ordered by the Commission having detected factors that could affect the systems and applications or the information received, generated, processed, stored, or transmitted in them. In the latter case, the Commission will determine the scope of the tests, as well as the deadlines for carrying them out.
Additional tests may be carried out at the discretion of the General Director, with the opinion of the Chief Information Security Officer, when there are significant changes in the systems and applications, or to perform them on previously reviewed systems and applications when there are critical vulnerabilities.
The General Director of the Institution must send to the Commission, within 20 business days of having finalized the tests, a report with the conclusions of these. In the submission made, care must be taken to use mechanisms that prevent access to the content of this report by unauthorized personnel.
V.
Classify the detected vulnerabilities according to the methodology approved by the risk committee.
VI.
Elaborate remediation plans regarding the findings of the reviews and tests referred to in subsections II, III, and IV above, considering the classification of subsection V of this article, as well as implementing defense mechanisms that prevent unauthorized access and use of the Technological Infrastructure.
The remediation plans referred to in the previous paragraph must be validated by the Chief Information Security Officer. Likewise, such plans must contain, at least, the indication of the personnel responsible for their implementation and execution, as well as the deadlines for this, detail of activities carried out and to be carried out, as well as the technical, material, and human resources employed. The aforementioned remediation plans must be elaborated once the vulnerabilities are identified and sent to the Commission within a period of 10 business days.
In addition to what is stated in the previous paragraph, in the case of short, medium, or long-term projects in the remediation plans, they must be incorporated into the Security Master Plan.
VII.
Implement follow-up processes for compliance with the aforementioned remediation plans, which must be verified by the Chief Information Security Officer.
VIII.
Implement the annual training programs referred to in subsection V of Article 69 of these provisions, as well as those on awareness in the matter of information security, directed to all personnel and clients including, if applicable, third parties who provide services to them, in which, among other aspects, the roles and responsibilities that Users of the Technological Infrastructure have in this regard are contemplated.
IX.
Proactively and iteratively search for fraud alerts, as well as threats, such as phishing email campaigns, fake websites, disclosure of databases with Public User information, alteration of ATMs or point-of-sale terminals, and identity theft, among others, that could affect the information security of the Public User, as well as actions for their protection considering, at least, the following:
a)
The continuous investigation, collection, processing, and analysis of information that comes from any source related to the products and services offered by the Institution, which may constitute indications or evidence that security controls have been evaded, representing a threat to the information or resources of the Public User.
The indications or evidence referred to in the previous paragraph will be kept in a record which must be contained in the database referred to in the first paragraph of Article 168 Bis 17 of these provisions.
b)
The implementation of proactive processes to protect the information or resources of clients when the indications or evidence mentioned in subsection a) above occur, such as blocking and replacement of disposal means, change of authentication data, and notifications, among others.
c)
That it have communication procedures and security recommendations with affected clients, to inform them about the remediation processes that the Institution will carry out and, if applicable, the measures that the client themselves must adopt, such as changing passwords, verifying balances and transactions, installing antivirus, installing malware detection software, reviewing devices, and reinstalling applications, among others.
The terms and conditions for carrying out the processes by which the activities mentioned in this subsection are carried out must be documented in the respective policy and procedure manuals, in which it must be provided that the Institution will maintain evidence of the carrying out of such activities.
X.
Implement controls that allow the Institution to ensure the confidentiality, integrity, and availability of the Public User's information and the Institution's own information or access to the Technological Infrastructure, by its employees or personnel who have access to it, which guarantee that such information and Technological Infrastructure are not altered or cause an impact on the Institution or on its clients' resources. Such controls must be implemented from the respective hiring until their termination.
Article 168 Bis 13.- Institutions must have a person who serves as Chief Information Security Officer, known as CISO by its English acronym (Chief Information Security Officer).
The Chief Information Security Officer must be designated by the General Director and occupy the level immediately below that of the General Director, reporting directly to them. They will be responsible for information security matters of the Institution and must respond to requirements formulated by authorities and within the Institution in said matter.
The Chief Information Security Officer must not have conflicts of interest regarding areas of information technology, audit, and Business Units within the Institution and cannot perform the functions of the persons in charge of the implementation and operation of the information security of the Institution itself.
Article 168 Bis 14.- The Chief Information Security Officer of the Institutions must:
I.
Participate in the definition and verify the implementation and continuous compliance of the security policies and procedures indicated in Article 168 Bis 11 of these provisions.
II.
Elaborate the Security Master Plan, which must contain, for each project defined, the project name, objective, scope, start and end dates, involved areas, and projected investment. The scope must include, among others, the magnitude of the works.
III.
Verify at least annually, the definition of access profiles to the Institution's Technological Infrastructure, whether own or provided by third parties, according to job profiles (functional segregation), including those with high privileges such as operating system, database, and application administration.
IV.
Ensure at least annually or earlier in the event of an Information Security Incident, the correct assignment of access profiles to Users of the Technological Infrastructure. The function referred to in this subsection may be carried out through representative and random samples.
Likewise, they will be responsible for the temporary authorization of access by exception, such as those of users of development environments with access to production environments, access due to contingency events, or any other privileged access that does not correspond to the policy determined by the Institution. Likewise, they must have a record containing the name of the User of the Technological Infrastructure, associated application, environment, reason for the exception, and start and end date of the assignment.
V.
Approve and verify compliance with the measures that have been adopted to remedy deficiencies detected as a result of the functions referred to in subsections III and IV of this article, as well as the findings of both internal and external audits related to the Technological Infrastructure and information security.
VI.
Manage information security alerts communicated by the Commission or other means, as well as Information Security Incidents, considering the stages of identification, protection, detection, response, and recovery.
VII.
Coordinate and preside over the team for the detection and response to Information Security Incidents within the Institution.
VIII.
Inform the Audit Committee and the Institution's risk committee or the Committees designated for this purpose, in the session immediately following the verification of the Information Security Incident in question, regarding the actions taken and the follow-up to measures to prevent or avoid the recurrence of the aforementioned incidents.
IX.
Validate the definition of the security mechanisms mentioned in Annex 71 of these provisions, as well as verify their compliance.
X.
Propose and coordinate the training and awareness programs in the matter of information security within the Institution and towards the Public User, and verify their effectiveness.
XI.
Present monthly to the General Director the management report in the matter of information security. This report must be made to the other committees or Board, as determined by the General Director or at their request.
XII.
Regarding the indicators referred to in numeral 7 of subsection a) of subsection III of Article 86 of these provisions, in the matter of information security, they must consider as
risk indicators at least those established in Annex 72 of these provisions, and report the result of the evaluation of said indicators to the Board, as well as to the Audit Committee, Risk Committee, or the committee constituted by the Institution for such purposes.
XIII.
Be responsible for implementing the regulation on information security issued by other financial authorities.
Institutions must ensure that the Chief Information Security Officer has access to the records of persons who have access to information related to the operations in which the Institution itself intervenes, including those located abroad and of the Users of the Technological Infrastructure who have high privileges, such as administration of operating systems and databases, as well as their service providers.
Institutions that belong to a financial group subject to the supervision of the Commission or that are part of Consortia or Business Groups that have a financial entity subject to the supervision of said Commission, may assign the functions of the Chief Information Security Officer to the person performing such activities in the financial entity supervised by the Commission, provided that such person complies with Article 168 Bis 13 of these provisions.
Article 168 Bis 15.- The Chief Information Security Officer of the Institutions may support the exercise of their functions with information security representatives from the different Business Units called operational information security officers, who will be responsible for the application of information security policies and processes in their respective Business Units, contributing to management processes, risk reporting, compliance evaluations, and security intelligence.
These operational officers will have the following functions:
I.
Verify the application of information security policies and procedures in their Business Unit, reporting on this management to the Chief Information Security Officer at least monthly.
II.
Report to the Chief Information Security Officer any risk or eventuality that could impact information security.
III.
Propose to the Chief Information Security Officer the adoption of additional information security controls.
Operational information security officers must stay updated regarding applicable regulations in this matter and may recommend to Business Unit personnel the adoption of information security measures that have previously been authorized by the Chief Information Security Officer.
Article 168 Bis 16.- In the event that an Information Security Incident occurs that meets any of the requirements referred to in paragraphs a) to d) of fraction I of this article in: (i) the components of the Institution's Technological Infrastructure; (ii) customer service channels, such as Electronic Media, Bank Offices, or Institution commissionaires; or (iii) the technological infrastructure of any third party that affects the operation or the Institution's Technological Infrastructure, the General Manager of the Institution must:
I.
Provide for the necessary measures to inform the Commission immediately of Information Security Incidents, via email sent to the account Ciberseguridad- CNBV@cnbv.gob.mx or through other means indicated by said Commission, generating an electronic receipt. In such notification, at least the date and time of the start of the Information Security Incident in question must be indicated, and, if applicable, whether it continues or has concluded and its duration; a description of said incident, as well as an initial assessment of the impact or severity.
The Information Security Incidents that must be reported immediately are those that update at least one of the following scenarios:
a)
It generates economic loss, information loss, or interruption of the Institution's services.
b)
Its mode of operation, including exploited vulnerabilities, could be replicated in other Institutions.
c)
It could represent an impact on the Institution's clients, the stability of the financial or payment system, or on central payment systems, their service providers, clearing houses, or securities depository institutions.
d)
Any other considered serious at the Institution's judgment.
Additionally, Institutions must send via email to the Commission at the account Ciberseguridad-CNBV@cnbv.gob.mx or through other means indicated by said Commission, within 5 business days following the identification of the Information Security Incident in question, the information contained in Annexes 64 and 64 Bis of these provisions.
Institutions must conserve and keep available to the Commission, for the period indicated in Article 168 Bis 17 of these provisions, the records of Information Security Incidents that do not meet any of the characteristics mentioned in the previous paragraphs.
II.
Carry out an immediate investigation into the causes that generated the Information Security Incident and establish a work plan describing the actions to be implemented to eliminate or mitigate the risks and vulnerabilities that facilitated the mentioned incident. This plan must indicate, at least, the personnel responsible for its design, implementation, execution, and monitoring, deadlines for execution, as well as technical, material, and human resources, and must be sent to the Commission within a period not exceeding 15 business days after the Information Security Incident concluded.
When the Information Security Incident refers to Sensitive Information in the custody of the Institution or third-party service providers being extracted, lost, deleted, altered, or if Institutions suspect any act involving unauthorized access to such information, the General Manager or the person they designate must notify clients of the possible loss, extraction, alteration, loss, or unauthorized access to their information, within the following 48 hours from when the Information Security Incident occurred or was known, through the notification means the client has indicated for such effect, in order to prevent them from risks derived from the misuse of information that has been extracted, lost, deleted, or altered, informing them of the measures they must take and, if applicable, the replacement of corresponding disposal means or the substitution of necessary Authentication Factors. The evidence of this notification must be included in the result of the investigation mentioned in the previous paragraph.
Article 168 Bis 17.- Institutions must keep a database record of incidents, failures, or vulnerabilities detected in the Technological Infrastructure, which must include at least information related to the detection of failures, operational errors, attempts at computer attacks and those effectively carried out, as well as loss, extraction, alteration, loss, or misuse of information of Technological Infrastructure Users, where the date of the event and a brief description of it, its duration, affected service or channel, affected clients and amounts, as well as corrective measures implemented are contemplated.
The information referred to in this article must be backed up in the means determined by the Institutions and conserved for at least 10 years. "
" Article 169.- Institutions must document in manuals the policies and procedures related to the operations of their object, including those related to the functioning of their Technological Infrastructure, which must be consistent with the objectives and guidelines of the Internal Control System, as well as describe the functions of the Institution's Internal Audit.
. . . "
" Article 315 Bis.- . . .
I.
Ordering clients must register instructions for payment of the order indicating beneficiary data, including full name, date of birth, and Mobile Phone Number. Likewise, the individualized amount assigned to each of them must be indicated, which cannot exceed the equivalent in national currency to Medium-Value Monetary Operations.
II. to V.
. . .
. . . "
" Article 316 Bis 10 .- . . .
I. to IV.
. . .
V.
Regarding the Electronic Banking service using debit and credit cards, with the certifications indicated below:
a)
Certifications of security standards of the card industry, including among others: the data security standard (PCI-DSS), the data security standard for payment applications (PA-DSS), and security requirements and PIN transactions (PTS) or their equivalents or those that, in the Commission's judgment, allow the proper protection of stored, transmitted, or processed information.
b)
Certification according to the interoperability standard for debit and credit cards known as EMV, levels 1 (interfaces, physical, electrical, and transport) and 2 (payment application selection and transaction processing), if applicable, those other standards that, in the Commission's judgment, satisfy this requirement and allow adequate interoperability. The foregoing only applies to Access Devices for Integrated Circuit Card Banking operations where the information to perform operations is taken directly from the integrated circuit of the card. "
" Article 316 Bis 12.- Repealed. "
" Article 316 Bis 14.- Institutions must keep in databases all operations carried out through the Electronic Banking service that are not recognized by their Users and that, at least, include information related to operations not recognized by Users and the procedure that, if applicable, the User has promoted, such as claim folio, claim date, cause or reason for the claim, operation date, source account, product type, Electronic Banking service in which the operation was made, amount, status of the claim, resolution, resolution date, amount credited, amount recovered, and amount lost.
. . . "
" Article 316 Bis 17.- Repealed. "
" Article 316 Bis 20.- Repealed. "
TRANSITIONAL PROVISIONS
FIRST.- This Resolution will enter into force the day following its publication in the Official Journal of the Federation, except for what is provided in the following transitional articles.
SECOND.- The norms contained in Article 86, fraction III, paragraph b), numeral 3, which is amended, and 168 Bis 11 fractions II, III paragraph b), IV, VI, paragraphs b) to e), IX, last paragraph; 168 Bis 12 fractions II, III, VIII and 168 Bis 14, fraction VI, which are added by this Resolution, will enter into force six months after their publication in the Official Journal of the Federation.
The obligations of Article 168 Bis 11, regarding the technological infrastructure requirements, as defined in this Resolution, provided by third parties contracted by credit institutions prior to the entry into force of this instrument, must be complied with within a maximum period of three years counted from the entry into force of this Resolution or at the time of renewal of the respective contract, whichever occurs first. Contracts with third parties made by credit institutions for the provision of technological infrastructure, contracted from the start of the validity of this Resolution, must comply with the requirements of Article 168 Bis 11, within six months counted from the entry into force of this instrument.
THIRD.- The obligations contained in Articles 168 Bis 11 fractions VI, paragraph a), X, XIII, XV; 168 Bis 12 fractions I, V; 168 Bis 13; 168 Bis 14 fractions I, II, IV second paragraph, VII, VIII, XI, XII, XIII and second paragraph of said article, which are added by this Resolution, will enter into force nine months after their publication in the Official Journal of the Federation.
The institutions referred to in Article 2, fraction II, of the Credit Institutions Law, must make the designation referred to in Article 168 Bis 13, twelve months after its publication in the Official Journal of the Federation.
Until the designation of the person mentioned in Article 168 Bis 13 of this Resolution is carried out, credit institutions will be obliged to carry out the respective functions through the person who, at the entry into force of this Resolution, is in charge of information security surveillance.
FOURTH.- The obligations contained in Articles 168 Bis 11 fractions VI, paragraph f), VIII, XI, XII, XIV first and second paragraphs; 168 Bis 12 fractions IV, VI, VII, IX and X; 168 Bis 14 fractions III, IV first paragraph, V, IX, X; as well as Article 316 Bis 10, fraction V regarding merchants and for the institutions themselves to provide for in the security master plan, as defined in this Resolution, which are added, will enter into force twelve months after their publication in the Official Journal of the Federation.
FIFTH.- The obligation contained in Article 168 Bis 11, fraction III, paragraph a), which is added by this Resolution, will enter into force eighteen months after its publication in the Official Journal of the Federation.
SIXTH.- The norms contained in Articles 15 Bis, fraction VI, paragraph c); 164, fraction VI, paragraphs b) and c); and 316 Bis 17, will be repealed six months after the publication in the Official Journal of the Federation of this Resolution.
SEVENTH.- The norms contained in Articles 15 Bis, fraction V, paragraph a) and 166, fraction V, will be repealed nine months after the publication in the Official Journal of the Federation of this Resolution.
EIGHTH.- The norms contained in Articles 15 Bis, fraction V, paragraph d), 164, fraction V, paragraphs g) and h) and 316 Bis 20, will be repealed twelve months after the publication in the Official Journal of the Federation of this Resolution.
Sincerely,
Mexico City, November 15, 2018.- The President of the National Banking and Securities Commission, José Bernardo González Rosas.- Signature.
ANNEX 64
Incidents of Impact in Information Security
I.
Institution Information
a)
Name of the Institution.
b)
Full name of the Chief Information Security Officer, as well as their phone number and email address.
II.
Detailed Information of the Information Security Incident
Description of the Information Security Incident
a)
Date and time it occurred
b)
Date and time it was detected
c)
Duration of the incident
d)
Location of the affected installation (data center, Bank Office)
e)
Is the information involved in the incident managed by third parties? Yes ( ) No ( )
f)
If the answer to paragraph e) is affirmative, detail provider data (name, address and contact data, email, phone, among others)
Impact Caused by the Information Security Incident
g)
Can the incident cause monetary loss for customers or for the institution itself? Yes ( ) No ( )
h)
Is it viable to recover direct (own management) or indirect (through insurance) the possible monetary loss, through other institutions or financial entities? Yes ( ) No ( )
i)
Have other incidents related to the one reported been identified, whether by origin, mode of operation or impact? Yes ( ) No ( )
j)
Indicate, if applicable, the type of information compromised with the Information Security Incident, according to the following tables:
Compromised Client Personal Information
Names Yes ( ) No ( )
Addresses Yes ( ) No ( )
Phone Numbers Yes ( ) No ( )
Email Addresses Yes ( ) No ( )
Biometric data (fingerprints, iris or retina patterns or facial recognition, among others) Yes ( ) No ( )
Other(s):
Account or Balance Information
Debit, credit or other card numbers Yes ( ) No ( )
Account Numbers Yes ( ) No ( )
Passwords or personal identification numbers Yes ( ) No ( )
User Identifiers Yes ( ) No ( )
Credit Limits Yes ( ) No ( )
Balances Yes ( ) No ( )
Other(s)
Institution Information
Access Keys Yes ( ) No ( )
Security Configurations Yes ( ) No ( )
Port or Service Identification Yes ( ) No ( )
IP Addresses of components or services Yes ( ) No ( )
IP Addresses of internal components Yes ( ) No ( )
Access to internal network segments Yes ( ) No ( )
Software versions, operating systems or databases Yes ( ) No ( )
Vulnerability Identification Yes ( ) No ( )
Other(s)
III.
Classify the reported Information Security Incident based on the following definitions:
Class of Information Security Incidents
a) Physical Attacks
Sabotage Yes ( ) No ( )
Vandalism Yes ( ) No ( )
Theft of devices Yes ( ) No ( )
Information leak in physical media Yes ( ) No ( )
Unauthorized physical access Yes ( ) No ( )
Coercion Yes ( ) No ( )
Extortion Yes ( ) No ( )
Terrorist attack Yes ( ) No ( )
Other(s):
b) Unintentional or accidental damage, information loss or asset loss
Improperly shared information Yes ( ) No ( )
Errors or omissions in systems or devices Yes ( ) No ( )
Errors in procedures or controls Yes ( ) No ( )
Unauthorized changes to data Yes ( ) No ( )
Loss of information or devices Yes ( ) No ( )
Other(s):
c) Incidents due to natural or environmental disasters
Earthquakes Yes ( ) No ( )
Floods Yes ( ) No ( )
Hurricanes Yes ( ) No ( )
Fires Yes ( ) No ( )
Radiation Yes ( ) No ( )
Corrosions Yes ( ) No ( )
Explosions Yes ( ) No ( )
Other(s):
d) Incidents due to failures or malfunctions
Devices Yes ( ) No ( )
Systems Yes ( ) No ( )
Communications Yes ( ) No ( )
Services Yes ( ) No ( )
Third-party equipment Yes ( ) No ( )
Supply chain Yes ( ) No ( )
Other(s):
e) Incidents due to interruption or lack of supplies
Absence of personnel Yes ( ) No ( )
Strikes Yes ( ) No ( )
Energy Yes ( ) No ( )
Water Yes ( ) No ( )
Telecommunications Yes ( ) No ( )
Other(s):
f) Incidents due to data interception
Espionage Yes ( ) No ( )
Messages Yes ( ) No ( )
Wardriving Yes ( ) No ( )
Man-in-the-middle attacks Yes ( ) No ( )
Session hijacking Yes ( ) No ( )
Sniffers Yes ( ) No ( )
Messaging theft Yes ( ) No ( )
Other(s):
g) Incidents due to malicious activity to take control, destabilize or damage a computer system
Identity theft Yes ( ) No ( )
Phishing Yes ( ) No ( )
Denial of service (DOS, DDOS) Yes ( ) No ( )
Malicious code (malware, trojans, worms, code injection, virus, ransomware) Yes ( ) No ( )
Social engineering Yes ( ) No ( )
Certificate violation (site spoofing, fake certificates) Yes ( ) No ( )
Hardware manipulation (anonymous proxies, skimmers, installation of sniffers) Yes ( ) No ( )
Information alteration (address spoofing and routing tables, DNS poisoning, configuration alteration) Yes ( ) No ( )
Abuse of information security review tools Yes ( ) No ( )
Brute force attacks Yes ( ) No ( )
Abuse of authorizations Yes ( ) No ( )
Organized crime Yes ( ) No ( )
Hacktivists Yes ( ) No ( )
Government or affiliated groups Yes ( ) No ( )
Terrorists Yes ( ) No ( )
Insiders Yes ( ) No ( )
Other(s):
h) Incidents originating from legal aspects
Violation of contractual clauses Yes ( ) No ( )
Violation of confidentiality agreements Yes ( ) No ( )
Adverse decisions (judicial resolutions in the same jurisdiction or in others) Yes ( ) No ( )
Other(s):
i)
Others (specify)
IV.
Indicate in the following tables the classification in which the incident is located using the concepts from the following catalog:
Specify which of the following categories the incident falls into:
Incident Type Catalog
Key Type
1 Cybersecurity ( )
2 Identity Spoofing ( )
3 Assault/Theft ( )
4 Physical Intrusion ( )
5 Information Loss ( )
999 Other ( )
Indicate the business line(s) affected by the incident:
Business Line Catalog
Key Product
101 Commercial Credits ( )
102 Consumer Credits ( )
103 Housing Credits ( )
104 Credit Cards ( )
105 Currencies ( )
106 Derivatives ( )
107 Repo ( )
108 SPEI/SPID/SWIFT ( )
109 Securities and Investment Instruments ( )
110 Savings, checking, etc. accounts ( )
112 Non-Banking Products ( )
199 Other ( )
Indicate the channels affected by the incident:
Affected Channel Catalog
Key Channel
201 Internet Operations Individuals ( )
202 Internet Operations Legal Entities ( )
203 E-commerce ( )
204 Telephone Banking ( )
205 Telephone Commerce ( )
206 ATMs ( )
207 Point of Sale Terminal ( )
208 Branches ( )
209 Correspondents ( )
210 Mobile Payment ( )
211 Mobile Banking ( )
212 Movement generated by the Bank ( )
213 Other Banks ( )
299 Other ( )
Indicate the type of asset affected by the incident:
Affected Asset Catalog
Key Impacted Asset
301 Statements ( )
302 Card Plastics ( )
303 Checkbooks ( )
304 PINs ( )
305 Passwords ( )
306 Databases ( )
307 TOKEN ( )
399 Other ( )
Name and signature of the Chief Information Security Officer
ANNEX 64 Bis
Information Security Incident Report
I.
Institution Information
a)
Name of the Institution.
b)
Full name of the Chief Information Security Officer, as well as their phone number and email address.
II.
Detailed Information of the Information Security Incident
a)
Attach the following information in encrypted digital media:
Description of the Information Security Incident.
Affected account numbers.
Status of affected accounts (blocked, suspended, active).
Affected network zone (internet, internal network, administration network, among others).
Type of affected system (file server, web server, email service, database, workstations, whether desktop or mobile, among others).
Operating system (specify version).
Protocols or services of the impacted components.
Number of components of the Institution's systems affected.
Applications involved (specify version).
Information on the compromised device, if applicable (brand, software version, firmware, among others).
Impact on service (considering any disruption) caused by the Information Security Incident.
Amount of loss in pesos, if applicable.
Amount recovered in pesos, if applicable.
Status of the Information Security Incident (Resolved or Unresolved).
Indicate whether the Information Security Incident has been disclosed to any authority. If affirmative, indicate the authority and the date.
Public IP addresses, email addresses, or domains from which the attack originates.
The communication protocol used, if applicable.
The URL in case of websites involved.
The malware or signature detected.
Detail the actions taken to mitigate the Information Security Incident, mentioning the persons responsible for implementing said mitigation actions.
Description of the results of the mitigation actions.
Actions to minimize damage in similar subsequent situations.
Other information that you consider should be known to this Commission.
Name and signature of the Chief Information Security Officer
ANNEX 71
TECHNICAL REQUIREMENTS FOR THE CAPTURE OF FINGERPRINTS AND FACIAL RECOGNITION AS BIOMETRIC DATA
I. Fingerprint Capture
The fingerprint records made by Institutions will consist of an image capture of the papillary ridges of the fingers on a contrasting surface by pressure, from which biometric data are obtained. This capture must consider controls that ensure they are obtained directly from the person, avoiding the recording of fingerprints from impressions on any material intended to simulate another person's fingerprint (live fingerprint test).
The first fingerprint capture process must consist of registering, first, the ten fingerprints of the employees, executives, and officials of the Institutions who will be in charge of registering customers' fingerprints. Second, the aforementioned employees, executives, and officials will proceed to capture at least six fingerprints of the Institution's customers. For this purpose, Institutions must assist the or those responsible for Internal Audit functions to verify what is provided in this paragraph.
The fingerprint capture process must prevent an employee, executive, or official of the Institution from registering their own fingerprints in place of the customer's. Institutions must at all times guarantee the integrity of the stored or transmitted biometric information, as well as its conservation, availability, and the impossibility of manipulation of such information. For the purposes of what is provided in this paragraph, Institutions must comply with at least the following:
a)
Logically and physically segregate the Technological Infrastructure on which the biometric information databases are maintained, including the segmentation of the different networks involved.
b)
Securely configure equipment, according to the type of Technological Infrastructure element, ports, services, permissions, access lists, manufacturer updates, and factory configuration.
c)
Establish access controls and identification and authentication mechanisms for all and each of the Users of the Technological Infrastructure, which allow them to be recognized unequivocally and ensure access only to persons expressly authorized for this purpose. Both mechanisms must include specific controls for those Users of the Technological Infrastructure with greater privileges, derived from their functions, such as database and operating system administration, including audit logs on all accesses.
d)
Have encryption mechanisms for information when it is transmitted or stored.
e)
Conduct tests aimed at detecting vulnerabilities and threats, as well as penetration testing on the different elements of the Technological Infrastructure in order to implement defense mechanisms that prevent unauthorized access and use of information.
f)
Implement controls for information conservation, including those regarding the integrity of stored information, which allow identifying any changes to the original data, as well as secure conservation and deletion that avoid at all times that they can be known by unauthorized third parties.
Institutions must use fingerprint readers of at least two fingers per reading (dual devices) for the first fingerprint capture procedure for the integration of their databases.
For the fingerprint capture process, the minimum image requirements are as follows:
Scanner Resolution (points per inch)
Depth (pixels)
Minimum Dynamic Range (gray levels)
500
8 bits
200
Platform (software and hardware) operation parameters for fingerprint capture
The applications and devices used in the fingerprint capture process on a contrasting surface by pressure, in order to integrate a database with such information, must consider at least the following requirements:
PARAMETER
DECISION
OBSERVATION
First fingerprint capture
Captured Image
Type of capture
M
Flat live.
Number of fingers
M
10 for employees, executives, and officials.
6 for customers as a minimum.
This, except for the exception established in this annex.
Finger position
MP
Fingers must be placed in the center of the plate with respect to its horizon and parallel to the capture surface.
Capture angle
MP
Fingers must be placed at 90° with a rotation of ±10° with respect to the plate's horizon.
Movement during capture
MP
Avoid sliding of fingerprints on the plate at the time of capture, to avoid smudged images.
Visualization
MP
The operator must observe capture information in real time.
Segmentation
MP
Proven by NIST in the test called "Slap Seg II test".
Sequence
M
Validate that fingerprints of each finger are not repeated during the same capture process.
Deduplication
M
Validate that the fingerprints of the Institution's customers or employees are not previously registered in the database with the information of another customer or employee of the Institution.
Devices
Dual
M
Certified EFTS annex F FAP 45.
Decadactylar (4-4-2)
M
Certified EFTS annex F FAP 60.
Sequence review.
Image
M
Generates RAW.
Preview of the taken image.
Information to be obtained from the device
M
The serial number is mandatory.
Optionally, the device must have Firmware version, manufacturer, and model.
Operation
Assisted
M
Yes. Hierarchical fingerprint capture and at least one fingerprint of the operator must be recorded, who must be registered biometrically in the Institution.
Analysis of quality parameters
M
In accordance with NFIQ.
Cleaning
MP
Clean the plate before each fingerprint capture for optical readers.
Lighting
MP
For optical devices, avoid light sources on the capture device.
Recapture
M
In case of not obtaining the minimum quality parameters, at least 3 attempts per fingerprint.
Transmission
Compression of 500 points per inch images (ppi, by its English acronym)
M
Single compression from RAW image. WSQ maximum 10:1.
Decision: M->Mandatory O->Optional MP->Best practice
In case that the applications, processes, parameters, or devices used in fingerprint capture do not comply with the requirements of this annex, Institutions must submit them to the approval of the Commission. Notwithstanding the foregoing, regarding the capture of customers' fingerprints, in no case may it be less than six fingerprints, except for the exception provided in this annex.
Exception to fingerprint capture
In case that customers, employees, executives, and officials of the Institutions are permanently unable to imprint their fingerprints on the respective readers, it must be specified that it is not possible to capture the fingerprint image due to amputations, grafts, malformation, permanent injury, prosthesis, disease, among others.
In any case, the greatest number of fingerprints possible must be captured, making the corresponding annotations in the file.
Authentication using the Institution's own fingerprint database
For the process by which fingerprint reading is made for authentication (1-to-1 matching) of already registered customers, and its use as Authentication Factor Category 4, if applicable, the image capture requirements are as follows:
Scanner Resolution (points per inch)
Depth (pixels)
Minimum Dynamic Range (gray levels)
300
4 bits
12
500
8 bits
80
PARAMETER
DECISION
OBSERVATION
Authentication
Captured Image
Number of fingers
O
1 to 4 depending on the type of reader.
Any finger
O
Yes. The sample against all records of the user.
Recapture
O
Yes. A minimum of three attempts is suggested.
Devices
Mobile
M
Certified EFTS annex F or PIV FAP 30.
Dual
M
Certified EFTS annex F FAP 45.
Decadactylar (4-4-2)
M
Certified EFTS annex F FAP 60.
Unidactylar
O
PIV is recommended.
Transmission
Format
O
One of the following: Proprietary Format, RAW Format, compressed image with ANSI INCITS 378 or ISO/IEC 19794-2 standards.
Decision: M->Mandatory O->Optional MP->Best practice
II. Operational Guidelines for Facial Recognition
In case that Institutions determine to obtain any facial recognition element from their customers, the applications and devices used in the process of capturing facial elements must consider at least the following requirements:
PARAMETER
DECISION
OBSERVATION
Facial image capture
Captured Image
M
2D Full Frontal, 24 bits color, minimum distance between eyes 90 pixels.
Digital and photographic requirements
M
ISO 19794-5 standard section 7.3, 7.4, 8.3, and 8.4.
Posture
M
Must allow a rotation of at least ±5° frontal in any direction (up, down, left, right).
Expression
M
Neutral facial expression. Smiles, winks, etc. must be avoided.
Gaze at the camera lens (with the exception of physical impediments).
Lighting
M
Balanced and distributed in each part of the face.
To achieve natural skin tones and avoid red eyes.
Depth of Field
M
The central pose of the complete face will be in focus from the crown to the chin and from the nose to the ears.
Glasses
M
The use of frames of any type will not be allowed.
Accessories
M
Only medical accessories are allowed (no hats, nor accessories that cover the face).
Impediments for the capture
M
Closed eyes.
Hair covering the eyes or forehead.
Elements obstructing the forehead.
Facial Hair
M
It is allowed.
PARAMETER
DECISION
OBSERVATION
Background
O
A uniform light-colored background will be used that contrasts with the face and hair; pale gray or white is recommended.
Operation
M
Controlled lighting environment.
Assisted
M
Yes.
Segmentation and feature extraction
M
Crop according to ICAO standard. Automatic feature extraction by software.
Quality review
M
Automatic by software; the ICAO standard for image quality must be evaluated.
Authentication
Image Capture
O
Same as facial image capture.
Number of Images
O
One full frontal.
Decision: M->Mandatory O->Optional MP->Best practice
The process of capturing elements for facial recognition must prevent an employee, executive, or official of the Institution from registering their own characteristics in place of the customer's. For this purpose, prior to starting the capture of customer information, Institutions must ensure that the data of their employees, executives, and officials have been captured previously. For this, Institutions must assist the or those responsible for Internal Audit functions to verify what is provided in this paragraph.
III. GLOSSARY
ANSI: American National Standards Institute, of the United States of America.
Authentication: The Process by which the User's identity is verified with the biometric data of fingerprints or face that Institutions have previously obtained. This process implies searches for stored patterns of a single individual (1-to-1).
Deduplication: The specialized data compression technique used to avoid duplicate copies of these.
EFTS (by its English acronym Electronic Fingerprint Transmission Specifications): The specifications for the transmission of biometric information of the Federal Bureau of Investigation of the United States of America (FBI).
FAP (by its English acronym FingerPrint Acquisition Profile): It is a subdivision of the categories applied to devices for fingerprint acquisition based on dimensions, number of simultaneous fingers to capture, image quality. When accompanied by a number (30, 45, 60) this indicates the capture area in inches (45=1.6 x 1.5; 60=3.2 x 3.0, etc.).
ICAO: The standard for passport photographs issued by the International Civil Aviation Organisation.
INCITS (by its English acronym InterNational Committee for Information Technology Standards): The central forum of the United States of America, dedicated to the creation of standards for technological innovation.
ISO/IEC: The standard for information security published by the International Organization for Standardization and the International Electrotechnical Commission.
NFIQ:
NIST Fingerprint Image Quality.
The quality standards of fingerprint images defined by NIST.
NIST:
National Institute of Standards and Technology.
PIV: The standard defined by NIST for 1-to-1 fingerprint verification (comparison of a fingerprint against a record).
Plate: The capture surface of the fingerprint capture device.
RAW: The format of the raw (unprocessed) image capture of a fingerprint.
Segmentation: The process by which the fingerprint image of each finger is individualized, based on an image compressed with WSQ or a single RAW image obtained from the reader, to obtain up to four independent images, one for each finger.
Slap Seg II Test: The test that evaluates the precision with which the algorithm segments images in multi-finger captures.
WSQ (by its English acronym Wavelet Scalar Quantization): The standard created by the FBI that defines the format for the compression of fingerprint images.
ANNEX 72
Information Security Indicators
The Chief Information Security Officer of the Institution, in relation to the information security indicators referred to in fraction XII of Article 168 Bis 14, of these provisions, must:
Evaluate these indicators, which must comply with the thresholds contained in this annex for each indicator. In case of defining different thresholds, the reason must be documented, which must be aligned with the Institution's risk tolerance level.
Define remediation plans for those risks where the evaluation results yield values that are within the medium and high risk thresholds established in this annex or, if applicable, those defined by the Institution, provided that these are in a high threshold for at least two consecutive periods.
Provide continuous maintenance, whether to add, eliminate, or update the existing key risk and information security performance indicators, which must always be aligned with the Institution's strategy and the Institution's Information Security Master Plan.
Measure and evaluate their evolution with the periodicity indicated in the following tables, or earlier in case of unusual events.
In case that not all assumptions apply, indicate that they are not applicable and explain the reason.
The type, subtype, and sub-class of events in which each of the indicators listed below are classified, have their basis in Section II of Annex 12-A of these provisions:
Type
Definition
Sub Type
Sub Class of Events
Examples
I. Internal Fraud
Losses derived from any type of action aimed at defrauding, improperly appropriating goods, or well, bypassing regulations, laws or corporate policies (excluding diversity / discrimination events) in which at least one internal party to the Institution is involved.
1.1 Unauthorized Activities.
1.1.1 Undisclosed operations (intentional).
1.1.2 Unauthorized operations (with financial losses).
1.1.3 Incorrect valuation of positions (intentional).
Undisclosed operations;
unauthorized operations (with
financial
losses);
incorrect valuation
of positions, and
intentional omission
of regulations.
1.2 Internal Theft and Fraud.
1.2.1 Fraud / credit fraud / worthless deposits.
1.2.2 Extortion / embezzlement / theft.
1.2.3 Misappropriation
of assets.
1.2.4
Willful destruction of assets.
1.2.5
Internal Forgery.
1.2.6 Utilization
of bounced checks.
1.2.7
Smuggling.
1.2.8 Appropriation of
accounts, identity, among others.
1.2.9 Non-compliance / tax evasion (intentional).
1.2.10
Bribery.
1.2.11 Abuse of
insider information (not for the benefit of the company).
Theft;
embezzlement;
misappropriation;
destruction of
assets;
forgeries;
identity theft; and
bribes;
manipulation of
accounts.
1.3. Security of the
systems.
1.3.1 Breach of security systems.
1.3.2 Damage from cyber attacks.
1.3.3 Theft of
information (with financial losses).
1.3.4 Inappropriate
use of access keys and/or authorization levels.
Abuse and use of
privileged or
confidential information;
alteration of
computer applications; theft
of passwords, and
prohibited computer
accesses.
II. External Fraud
Losses derived from any type of action aimed at defrauding, improperly appropriating goods or bypassing the legislation, by a third party.
2.1 External Theft and Fraud.
2.1.1 Robbery / fraud / extortion / bribery.
2.1.2 External Forgery / Identity Impersonation.
2.1.3
Fraudulent use of checks.
2.1.4 Use and/or disclosure of
insider information.
2.1.5
Industrial Espionage.
2.1.6
Smuggling.
Forged or manipulated
documentation (checks,
transfers,
etc.); identity theft;
improper dispositions;
counterfeit coins;
damaged or
out of legal circulation banknotes; robberies in the
Institution's premises, in
internal mail, cash transports or in
postal packages, and improper use of
stolen, forged,
stolen or blacklisted cards.
2.2 Security of the Systems.
2.2.1 Breach of security systems.
2.2.2 Damage from cyber attacks.
2.2.3 Theft of
information (with financial losses).
2.2.4 Inappropriate
use of access keys and/or authorization levels.
Unauthorized computer access;
manipulation of
computer applications;
damage from cyber attacks, and
theft of
information.
VI. Incidents
in the Business and
Failures in the
Systems
Losses derived from incidents in
the business and from
system failures.
6.1 Systems
6.1.1 Hardware.
6.1.2 Software.
6.1.3
Telecommunications.
6.1.4
Interruption / incidents in the
supply.
Interruption /
incidents in the
supplies and
communication lines;
errors in the
computer programs;
failures
in hardware and
software;
sabotage;
business interruptions;
computer failures and
virus programming.
ID
Name
Description
Domain
Type
Sub Type
Sub Class of Events
Type of
Indicator
Period
Unit of Measurement
Calculation
Variable X
Variable Y
High Risk
Medium Risk
Low Risk
KRI0001
Incidents
via direct
attacks against the
internal systems.
Number of incidents
that have been
originated by attacks
towards the internal systems of the
Institution, in the period
established.
Logical attacks.
II. External Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Reactive.
Quarterly.
Quantity.
Variable X
Number of
identified incident
cases.
More than 1.
Equal to 1.
Equal to 0.
KRI0002
Cases of fraud
in Electronic Banking.
Percentage of cases
where fraud is identified,
that has been
originated by attacks
towards the electronic banking systems of the
Institution, in the period
established.
Logical attacks.
II. External Fraud
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Reactive.
Monthly.
Percentage.
(X/Y)*100
Number of
cases of
fraud in
electronic banking.
Number of
electronic banking
users
active.
More than
.01
%.
Between 0.005 %
and 0.01 %.
Less than
0.005 %.
KRI0003
Equipment of the
Technological Infrastructure
whose
security configuration
is managed.
Percentage of equipment
of Technological Infrastructure within the
platform and/or
process of review of
secure configuration standards,
with respect to the total of
the equipment of the
Institution during the
established period.
Compliance.
II. External Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Preventive.
Monthly.
Percentage.
(X/Y)*100
Number of
equipment within
the
platform or
process of
review of
secure configuration
standards.
Total number
of equipment.
Less than
85 %.
Entre 85 % and
95
%.
More than 95 %.
KRI0004
Level of
compliance with
secure configuration
of UNIX/Linux
servers.
Average percentage of
compliance level of UNIX/
Linux servers included
within the tool
and/or process of review
of secure configuration
standards.
Compliance.
II. External
Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Preventive.
Monthly.
Percentage
average.
Average(X)
% of
compliance
of the
secure
configuration
standard
of each of
the UNIX/Linux
Servers.
Less than
90 %.
Between 90 % and
95
%.
More than 95 %.
KRI0005
Users with
inadequate roles and
profiles.
Percentage of users
with inadequate profiles within
the applications of the
Institution, with respect
to the total number of users in
all applications
of the Institution.
Compliance.
I. Internal
Fraud
1.3. Security
of the
systems.
1.3.3 Theft of
information (with
financial losses).
1.3.4 Inadequate
use of access keys
and/or authorization
levels.
Corrective.
Semi-annually.
Percentage.
(X/Y)*100
Number of
users with
incorrect
profiles,
considering
all
applications.
Total number
of users
considering
all
applications.
More than 3
%.
Between 1% and 3 %.
Less than 1
%.
KRI0006
Applications without
roles and profiles.
Percentage of
applications that
do not have the capacity
for role and permission
profiling, or that
such profiles are not
implemented, this
with respect to the total
of applications.
Compliance.
I. Internal
Fraud.
1.3. Security
of the
systems.
1.3.3 Theft of
information (with
financial losses).
1.3.4 Inadequate
use of access keys
and/or authorization
levels.
Corrective.
Quarterly.
Percentage.
(X/Y)*100.
Number of
applications
without capacity
for
profiling,
or profiling not
implemented.
Total number
of
applications.
More than 5
%.
Between 2 % and 5 %.
Less than 2
%.
KRI0007
Information security
incidents in general
Total number of
incidents reported
during the established
period regarding
information security.
Information.
Applies to:
I. Internal
Fraud
II. External
Fraud
VI.
Business
Incidents
and System
Failures.
Apply to:
1.3. Security
of the
systems
2.2 Security
of the
Systems.
6.1 Systems.
Apply to:
1.3.1 Breach of
security systems
1.3.2 Damage from
cyber attacks.
1.3.3 Theft of
information (with
financial losses).
1.3.4 Inadequate
use of access keys
and/or authorization
levels.
2.2.1 Breach of
security systems.
2.2.2 Damage from
cyber attacks.
2.2.3 Theft of
information (with
financial losses).
2.2.4 Inadequate
use of access keys
and/or authorization
levels.
6.1.1 Hardware.
6.1.2 Software.
6.1.3
Telecommunications.
6.1.4 Interruption /
incidents in the
Supply
Reactive.
Monthly.
Quantity.
Variable X.
Number of
security
information
incidents.
More than 5.
From 2 to 5.
Less than 2.
KRI0008
Obsolete and/or
outdated technological
platforms
Percentage of
technological
platforms that are
on obsolete versions and/or
without support from
the manufacturer
Infrastructure
.
II. External
Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Corrective.
Semi-annual
Percentage.
(X/Y)*10.
Number of
technological
platforms
obsolete.
Total of
technological
platforms.
More than 5
%.
Between 2 % and 5 %.
Less than 2 %
KRI0009
System failures
related to the
automated teller
machine network.
Number of system failures
related to the automated
teller machine network
lasting more than
10 minutes.
Infrastructure
.
VI.
Business
Incidents
and System
Failures.
6.1 Systems.
6.1.4 Interruption /
incidents in the
Supply.
Reactive.
Monthly.
Quantity.
Variable X.
Number of
system
failures.
More than 1.
Equal to 1.
Equal to 0.
KRI0010
Security incidents
from vulnerabilities
of systems
provided by
providers
(third parties).
Percentage of
security incidents
caused by
vulnerabilities in
systems and
technological
infrastructure provided
by providers
(third parties) that
do not belong to the
institution's payroll,
reported during the
established period, with
respect to the total
of security incidents.
Infrastructure
.
II. External
Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
2.2.2 Damage from
cyber attacks.
2.2.3 Theft of
information (with
financial losses).
2.2.4 Inadequate
use of access keys
and/or authorization
levels.
Reactive.
Monthly.
Percentage.
(X/Y)*100.
Number of
security incidents
attributed to
vulnerabilities
in systems
provided by
providers
(third parties).
Total number
of security
incidents.
More than 5
%.
Between 0.1 % and
5
%.
Less than 0.1
%.
KRI0011
Pending critical
vulnerabilities to be corrected detected in
ethical hacking
tests.
Number of
vulnerabilities in the
information systems
that, according to the
ethical hacking tests,
are classified
as critical, which
have more than one month
of age from
their date of detection.
Infrastructure
.
II. External
Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Preventive.
Monthly.
Quantity.
Variable X.
Number of critical
vulnerabilities
pending to be corrected with
age of
more than one
month.
More than 2.
Between 1 and 2.
Equal to 0.
KRI0012
Unavailability
of IT systems.
Average percentage of
downtime of the
systems against
the total time of the
established period.
Infrastructure
.
VI.
Business
Incidents
and System
Failures.
6.1 Systems.
6.1.4 Interruption /
incidents in the
Supply.
Reactive.
Monthly.
Percentage
Average.
Average(X).
Average of
downtime of
IT systems.
More than
0.5
%.
Between 0.25 %
and
0.5 %.
Less than
0.25 %.
KRI0013
Unavailability
of online
banking.
Percentage of time
downtime against
the total time of the
electronic banking
system against
the month in question.
Infrastructure
.
VI.
Business
Incidents
and System
Failures.
6.1 Systems.
6.1.4 Interruption /
incidents in the
Supply.
Reactive.
Monthly.
Percentage.
(X/Y)*100.
Time of
downtime of
electronic banking.
Total time
established
for electronic
banking.
More than
0.25 %.
Between 0.15 %
and
0.25 %.
Less than
0.15 %.
KRI0014
Critical and high
priority incidents
in production
environments.
Percentage of
incidents classified
as critical and high
priority in production
environments with respect
to the total incidents in
production.
Infrastructure
.
II. External
Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Reactive.
Monthly.
Percentage.
(X/Y)*100.
Number of
incidents in
production
classified
as critical.
Total number
of incidents
in production.
Greater than or
equal to
0.5
%.
Greater than 0% and
less than 0.5 %.
Equal to 0 %.
KRI0015
Components of the
technological
infrastructure
exposed to
the internet without
ethical hacking
tests and/or
vulnerability
analysis.
Percentage of the
components of the
technological
infrastructure of the
organization exposed to the internet to
which ethical hacking has not
been performed or
vulnerability
analysis, with
respect to the total
of equipment in more than 3
months.
Infrastructure
.
II. External
Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Corrective.
Quarterly.
Percentage.
(X/Y)*100.
Number of
assets
exposed to
the internet that have not
performed
ethical hacking tests or
vulnerability
analysis
.
Number of
assets
exposed to
the internet.
More than 3
%.
Between 1 % and 3
%.
Less than 1
%.
KRI0016
Pending critical
vulnerabilities to be corrected detected in the
vulnerability
analyses.
Number of
vulnerabilities in the
information systems
that, according to the
vulnerability
analyses, are
classified as
critical, which,
have more than one month
of age from
their date of detection.
Infrastructure
.
II. External
Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Quantity.
Variable X.
Total number of
critical
vulnerabilities.
More than 2
Between 1 and 2
Equal to 0
KRI0017
Fraud cases
reported by
electronic banking
clients.
Percentage of fraud cases
reported by
clients of the electronic
banking of the
Institution,
considering the number
total of electronic banking
clients in the
established period.
Infrastructure
.
II. External
Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Reactive.
Monthly.
Percentage.
(X/Y)*100.
Number of cases
of fraud
reported in
electronic
banking.
Number of
clients of
electronic
banking.
More than
0.005 %
Between 0.003 % and
0.005 %
Less than 0.003
%
KRI0018
Obsolete and/or
unsupported
Technological
Infrastructure.
Number of equipment and
Technological
Infrastructure, that are
on obsolete versions or
without support, in
comparison with all
active IT
infrastructure in the
established period.
Infrastructure
.
II. External
Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Corrective.
Quarterly.
Percentage.
(X/Y)*100.
Number of
equipment and
obsolete
infrastructure.
Total number
of active
equipment.
More than 5
%.
Between 2 % and 5 %.
Less than 2
%.
KRI0019
Servers without
antimalware
solution.
Percentage of
servers without
antimalware with respect to the total number of servers.
Malware.
II. External
Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y)*100.
Number of
servers without
antimalware.
Total number
of servers.
More than 6
%.
Between 3% and 6 %.
Less than 3 %.
KRI0020
Servers with
antimalware
signatures
outdated.
Percentage of
servers with
antimalware signatures
(malware signatures)
outdated
with respect to the total
of servers with
antimalware in each
Institution
Malware.
II. External
Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y)*100.
Number of
servers with
antimalware
signatures
outdated.
Total number
of servers
with
antimalware.
More than 6 %
Between 3% and 6 %
Less than 3 %
KRI0021
Workstations without
antimalware
solution
Percentage of
workstations without
antimalware with
respect to the total
equipment
Malware.
II. External
Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y)*100.
Number of
workstations without
antimalware.
Total number of
workstations.
More than 8
%.
Between 4% and 8 %.
Less than 4 %.
KRI0022
Workstations with
outdated
antimalware
signatures.
Percentage of
workstations that
have outdated
antimalware
signatures
(malware signatures)
with respect to the total
of computing equipment with
antimalware installed.
Malware.
II. External
Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y)*100.
Number of
workstations with
antimalware
signatures
outdated.
Number of
workstations
with
antimalware.
More than 8
%.
Between 4% and 8 %.
Less than 4 %.
KRI0023
Security incidents
attributed to
provider
personnel
(third parties).
Percentage of
security incidents
related to personnel
of providers
(third parties) that
do not belong to the
Institution's payroll,
reported during the
established period, with
respect to the total
of security incidents.
Incidents.
II. External
Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Reactive.
Monthly.
Percentage.
(X/Y)*100.
Number of
security incidents
related to
provider
personnel
(third parties).
Number of
total security incidents
of provider
personnel
(third parties).
More than 5
%.
Greater than 0 % and
less than 5 %.
Equal to 0 %.
KRI0024
Servers with
obsolete operating
system
versions.
Total percentage of
servers with
obsolete operating system
versions compared against
total number of
servers.
Software.
II. External
Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y)*100.
Number of
servers with
obsolete operating system
versions.
Total number
of servers.
More than
10
%.
Between 5% and 10 %.
Less than 5 %.
KRI0025
Production applications
with partial or
deficient compliance
of security
controls.
Percentage of
applications in
production with
partial or
deficient compliance,
with respect to
established security
policies,
in matters of
security, with respect
to the total number of applications.
Software.
II. External
Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Corrective.
Quarterly.
Percentage.
(X/Y)*100.
Number of
security controls
deficient in
applications in
production.
Total number
of security
controls.
More than 5 %.
Between 2 % and 5 %.
Less than 2 %.
KRI0026
Database managers (DBM)
with obsolete or
unsupported technology
versions.
Percentage of database managers (DBM),
which are versions of
obsolete technologies or not
supported by the
manufacturer, in
comparison with the total
of database managers
(DBM) active in the
established period.
Software.
II. External
Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Corrective.
Quarterly.
Percentage.
(X/Y)*100.
Number of database
managers
(DBM) obsolete
or unsupported.
Total number
database
managers
(DBM).
More than
10
%.
Between 5 % and 10
%.
Less than 5
%.
KRI0027
Obsolete or
unsupported
applications.
Percentage of
applications within
the Institution, which
are obsolete
or without support from
the manufacturer, in relation
to all active applications
during the
established period.
Software.
II. External
Fraud.
VI.
Business
Incidents
and System
Failures.
2.2 Security
of the
Systems.
6.1 Systems.
2.2.1 Breach of
security systems.
6.1.2 Software.
Corrective.
Quarterly.
Percentage.
(X/Y)*100.
Number of
obsolete or
unsupported
applications.
Total of
active
applications.
More than 5 %.
Between 2 % and 5 %.
Less than 2 %.
KRI0028
Windows and
UNIX/Linux servers
without
security patch
coverage.
Percentage of
servers without the
most recent security
patches in
Windows and UNIX/Linux
operating systems,
with respect to the total
of active servers
during the
established period.
Software.
II. External
Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y)*100.
Number of
servers without the
most recent security
patches
installed.
Total of
servers.
More than 5
%.
Between 2 % and 5 %.
Less than 2
%.
KRI0029
Workstations without
security patch
coverage.
Percentage of
workstations without the
most recent security
patches regardless of
the operating system
in question, with
respect to the total
of workstations of the
institution.
Software.
II. External
Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y)*100.
Number
of workstations without
the most recent security
patches
installed.
Total number of
workstations.
More than 3
%.
Between 1 % and 3 %.
Less than 1
%.
KRI0030
Database managers (DBM)
without security
patch
coverage.
Percentage of database
managers (DBM) without
coverage of the
most recent security
patches, with
respect to the total of database
managers (DBM)
during the
established period.
Software.
II. External
Fraud.
2.2 Security
of the
Systems.
2.2.1 Breach of
security systems.
Preventive.
Quarterly.
Percentage.
(X/Y)*100.
Number of database
managers
(DBM) without
coverage of
security
patches.
Total number
of database
managers
(DBM).
More than 5
%.
Between 2 % and 5 %.
Less than 2 %.
In the document you are viewing, there may be text, characters or objects that do not display correctly due to conversion to HTML format, so we recommend always taking the digitized image of the DOF or the PDF file of the edition as a reference. The content, form and scope of the published documents are the sole responsibility of their issuer.
INQUIRY
BY DATE
Su
Mo
Tu
We
Th
Fr
Sa
INDICATORS
Exchange Rate and Rates as of 29/08/2026
UDIS
8.809369
See more
SURVEYS
Did you like the new image of the Official Gazette of the Federation website?
No
Yes
Official Gazette of the Federation
Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our menu of services
Electronic address: dof.gob.mx
113
LEGAL NOTICE | SOME RIGHTS RESERVED © 2026
More like this from SHCP
SHCP published 14 documents in the last 30 days. We email you each new one the day it's published.