2018-11-27 | DOF 5544804

Added

Resolution modifying the general provisions applicable to credit institutions

The National Banking and Securities Commission modifies the general provisions applicable to credit institutions to strengthen the regulatory framework for information security and technological infrastructure. The resolution introduces new definitions for information security incidents and sensitive user information, mandates specific internal controls for authentication and operational contingency, and establishes a new section on information security requiring institutions to implement a control system ensuring the confidentiality, integrity, and availability of their technological infrastructure. It also updates reporting obligations for operational contingencies and replaces specific annexes regarding biometric data capture and security indicators.

Secretaria de Hacienda y Credito Publico logo

Mexico

Secretaria de Hacienda y Credito Publico

Click to view thumbnail

If the document is presented incomplete on the right margin, it is because it contains tables that exceed the default width. If this is the case, click here to view it correctly.

DOF: 27/11/2018

RESOLUTION modifying the general provisions applicable to credit institutions

A seal with the National Coat of Arms, which reads: United Mexican States.- Ministry of Finance and Public Credit.- National Banking and Securities Commission, is placed at the margin.

The National Banking and Securities Commission, based on the provisions of articles 52, eighth paragraph, and 96 Bis of the Credit Institutions Law, as well as 4, fractions XXXVI and XXXVIII; 16, fraction I, and 19 of the National Banking and Securities Commission Law, and

CONSIDERING

That in accordance with article 78 of the General Law for Regulatory Improvement and with the aim of reducing the compliance cost of these provisions, the National Banking and Securities Commission, through a resolution published in the Official Gazette of the Federation on June 26, 2017, reformed the "Resolutor modifying the General Provisions applicable to credit institutions" published in the same medium on January 6, 2017, with the objective of extending the deadline that credit institutions have to have 100% of the amount of preventive estimates for credit risks corresponding to non-revolving consumer credit portfolios, housing mortgages, and microcredits constituted, in accordance with the use of the new applicable methodology, while clarifying when this information must be disclosed in their financial statements, as well as in any public communication of financial information, and

That in order to be able to face risks and cyberattacks that could cause damage to credit institutions and to the execution of operations with clients, it is convenient to strengthen the regulatory framework on the security of their systems and technological infrastructures, as well as to reinforce the internal controls they must have, establishing a regime that seeks to guarantee the security of the technological infrastructure on which their operations are supported and the confidentiality, integrity, and availability of information, so that they have specific measures, tending to protect their information, certainty in their operation, and continuity of services, has resolved to issue the following:

RESOLUTION MODIFYING THE GENERAL PROVISIONS APPLICABLE TO

CREDIT INSTITUTIONS

SOLE.- Articles 1, fractions XIII, XXXIX, and current fraction LXXXI; 11, first paragraph; 12, fraction III; 15 Bis, fraction V, first paragraph; 51 Bis 3, fraction I and last paragraph; 51 Bis 5, fraction I; 51 Bis 9, fraction I; 86, fraction III, subsection b), numerals 1 to 3; 141, fraction III; 160, fraction III; 164, fraction IV, subsections f) and h); 164 Bis, fraction III; 166, fraction III; 169, first paragraph, 315 Bis, fraction I, and 316 Bis 14, first paragraph; are REFORMED; Articles 1, fractions LXXVI, LXXXIII, CXXXVI, and CXCII, with the remaining fractions being renumbered in order and as appropriate; 160, fraction XIV; Title Two, Chapter VI, Section Eighth Bis to be named "On Information Security" which comprises articles 168 Bis 11 to 168 Bis 17; 316 Bis 10, fraction V, as well as Annexes 64 Bis and 72; are ADDED; Articles 15 Bis, fraction V, subsections a) to e); 71, fraction IX; 86, fraction III, subsection b), numeral 3, subsections i. to vi.; 164, fraction V; 166, fraction V; 316 Bis 12; 316 Bis 17, and 316 Bis 20; are REPEALED; and Annexes 64 and 71 of the "General Provisions applicable to credit institutions", published in the Official Gazette of the Federation on December 2, 2005, and modified through resolutions published in the said Official Gazette on March 3 and 28, September 15, December 6 and 8, 2006; January 12, March 23, April 26, and November 5, 2007; March 10, August 22, September 19, October 14, and December 4, 2008; April 27, May 28, June 11, August 12, October 16, November 9, and December 1 and 24, 2009; January 27, February 10, April 9 and 15, May 17, June 28, July 29, August 19, September 9 and 28, October 25, November 26, and December 20, 2010; January 24 and 27, March 4, April 21, July 5, August 3 and 12, September 30, October 5 and 27, and December 28, 2011; June 19, July 5, October 23, November 28, and December 13, 2012; January 31, April 16, May 3, June 3 and 24, July 12, October 2, and December 24, 2013; January 7 and 31, March 26, May 12 and 19, July 3 and 31, September 24, October 30, December 8 and 31, 2014; January 9, February 5, April 30, May 27, June 23, August 27, September 21, October 29, November 9 and 13, December 16 and 31, 2015; April 7 and 28, June 22, July 7 and 29, August 1, September 19 and 28, and December 27, 2016; January 6, April 4 and 27, May 31, June 26, July 4 and 24, August 29, October 6 and 25, December 18, 26, and 27, 2017; January 22, March 14, April 26, May 11, June 26, July 23, August 29, and November 15, 2018, to remain as follows:

TITLES FIRST and FIRST BIS

...

TITLE TWO

...

Chapters I to V

...

Chapter VI

...

Sections First to Eighth

...

Section Eighth Bis

On Information Security

Section Ninth

...

Chapters VII to IX

...

TITLES SECOND to FIFTH ...

Annexes 1 to 63

...

Annex 64

Incidents affecting information security.

Annex 64 Bis

Report on Information Security Incidents.

Annexes 65 to 70

...

Annex 71

Technical requirements for the capture of fingerprints and facial identification as biometric data.

Annex 72

Information security indicators.

" Article 1.-

...

I. to XII.

...

XIII.

Authentication: the set of techniques and procedures used to verify the identity of:

a)

A User and their authority to perform operations through the Electronic Banking service, or a User of the Technological Infrastructure to access, use, or operate any component of the Technological Infrastructure.

b)

An Institution and its authority to receive instructions through the Electronic Banking service.

XIV. to XXXVIII.

...

XXXIX.

Operational Contingency: any event that hinders, limits, or prevents an Institution from providing its services or carrying out those processes that could have an impact on the Public User.

XL. to LXXV.

...

LXXVI.

Information Security Incident: an event that the Institution evaluates according to its management processes, which may:

a)

Endanger the confidentiality, integrity, or availability of a component or the entirety of the Technological Infrastructure used by an Institution or of the information that said infrastructure processes, stores, or transmits.

b)

Represent a loss, extraction, alteration, or misplacement of information.

c)

Constitute a violation of information security policies and procedures.

d)

Represent the materialization of a loss due to damage, interruption, alteration, or failures derived from the use of hardware, software, systems, applications, networks, and any other channel of information transmission in the provision of services, in Technological Infrastructures interconnected that allow interactions between people, processes, data, and components of information and telecommunications technologies, and which are caused or derive, among others, in unauthorized access, misuse of information or systems, fraud, theft of information, or in interruption of services, which puts at risk the confidentiality, integrity, and availability of information.

e)

Vulnerate the systems or components of the Technological Infrastructure with an adverse effect on the Institution, its clients, third parties, suppliers, or counterparties, commonly known as cyber-attacks.

LXXVII. to LXXXI.

...

LXXXII.

Sensitive Information or User Sensitive Information: information of the Public User, which contains names, addresses, phone numbers, or email addresses, or any other data that identifies said persons together with bank card numbers, account numbers, credit limits, balances, amounts, and other data of a financial nature, as well as User Identifiers or Authentication information.

LXXXIII.

Technological Infrastructure: computer equipment, data processing and communications facilities, communications equipment and networks, operating systems, databases, applications, and systems that Institutions use to support their operation.

LXXXIV. to CXXXV.

...

CXXXVI.

Security Master Plan: the document that establishes the security strategy of an Institution to ensure proper management of information security and avoid the materialization of Information Security Incidents that could negatively affect the Institution.

CXXXVII to CLIV.

...

CLV. to CXCI.

...

CXCII.

User of the Technological Infrastructure: the person, User, or physical or logical component that accesses, uses, or operates the Technological Infrastructure of the Institutions.

CXCIII. to CXCVII

... "

" Article 11.- Institutions in the development of Credit Activity, must have for each of the stages, processes, adequate personnel, and Technological Infrastructure that allow the achievement of their objectives in credit matters, adhering to these provisions, as well as to the methodologies, models, policies, and procedures established in their credit manual.

...

Article 12.-

...

I. and II.

...

III.

Maintain adequate controls that guarantee the confidentiality, integrity, and availability of information that ensure their security both physically and logically, as well as measures for the recovery of information in cases of Operational Contingency, in terms of Articles 164 Bis and 168 Bis 11 of these provisions.

IV.

... "

" Article 15 Bis.-

...

I. to IV.

...

V.

Maintain the confidentiality, integrity, and availability of information observing, in the case of systems managed by Institutions, the controls indicated in Article 168 Bis 11, as well as measures in cases of Operational Contingency in terms of Article 164 Bis of these provisions.

a) to e) Are repealed.

...

... "

" Article 51 Bis 3.-

...

I.

The detailed description of the mechanism, which must be approved by its Board of Directors, as well as of the Technological Infrastructure used in each part of the process.

II.

...

In any case, in the implementation of the approved mechanism for the formation of the fingerprint database, Institutions must first capture the fingerprints of their employees, executives, or officials who will be in charge of collecting those of clients, and subsequently collect those of their clients. Likewise, they must observe what is stated in the second and third paragraphs of section I of Annex 71 of these provisions " .

" Article 51 Bis 5 .- . . .

...

I.

The detailed description of the process, which must be approved by its Board of Directors, as well as the Technological Infrastructure used in each part of this.

II. and III.

...

... "

" Article 51 Bis 9.- . . .

I.

The detailed description of the process, which must be approved by the Board of Directors, as well as the Technological Infrastructure used in each part of this.

II. to VII.

...

... "

" Article 71.- . . .

I. to VIII.

...

IX.

Approve the methodology for classifying vulnerabilities in information security according to their criticality, probability of occurrence, and impact.

... "

" Article 86 .-

.

.

I. and II.

...

III.

...

a)

...

b)

...

Comply with what is established in Section Eighth Bis of Chapter VI of Title Two of these provisions.

Establish controls for the identification and resolution of those acts or events that could generate risks for the Institution derived from:

i.

The commission of fraudulent facts, acts, or operations through technological means.

ii.

The inadequate use by Users of the Technological Infrastructure.

Establish and implement policies and procedures for the classification of information and its treatment, according to the risk that the security of the information is violated determined by each of the Business Units and other operational areas of the Institution. This classification must be included in the manuals for Integrated Risk Management referred to in the last paragraph of Article 78 of these provisions and be used to evaluate and implement the necessary controls in the Technological Infrastructure and in operational processes, in order to preserve the confidentiality, integrity, and availability of the Institution's and its clients' information.

i. to vi.

Are repealed.

The Institution must evaluate situations that in terms of technological risk could affect its ordinary operation, which must be monitored permanently in order to verify the performance of the Integrated Risk Management process.

c)

...

... "

" Article 141 .- . . .

I. and II.

...

III.

Those that regulate and control matters related to the Technological Infrastructure, including automated data processing systems and telecommunications networks referred to in Article 52 of the Law.

IV.

... "

" Article 160 .- . . .

...

I. and II.

...

III.

Verify that the Technological Infrastructure that supports the operation and internal processes of the Institution, including accounting systems, credit portfolio operational systems, securities, or any other type, have mechanisms to preserve the integrity, confidentiality, and availability of information, that prevent its alteration and comply with the objectives for which they were implemented or designed, in terms of Article 168 Bis 11 of these provisions. Likewise, periodically monitor the Technological Infrastructure in order to identify potential failures and verify that it generates sufficient, consistent information and that it flows adequately.

...

IV. to XIII.

...

XIV.

Evaluate based on the annual work program referred to in fraction XI of this article, the management process of Information Security Incidents referred to in Article 168 Bis 14 of these provisions.

Penultimate paragraph. - Repealed.

... "

" Article 164.-

...

...

...

I. to III.

...

IV.

...

a) to e)

...

f)

Protect the integrity and proper maintenance of the Technological Infrastructure, including automated data processing systems and telecommunications networks referred to in Article 52 of the Law, as well as the integrity, confidentiality, and availability of information received, generated, processed, stored, and transmitted by these, in terms of Article 168 Bis 11 of these provisions. Additionally, procedures must be established so that clients can report the theft or loss of any of their Authentication Factors, even when Institutions operate through their agents.

g)

...

h)

Ensure that information security procedures, organizational structures, and policies are observed in accordance with the Institution.

i)

...

V.

Is repealed.

VI. to IX.

...

...

...

Article 164 Bis .- . . .

...

I. and II.

...

III.

Inform the Commission of Operational Contingencies, by email sent to contingencias@cnbv.gob.mx, or through other means that the Commission itself makes available, an electronic receipt must be generated, always when these interruptions have a duration of at least sixty minutes and update any of the following circumstances:

a)

When failures occur in the Technological Infrastructure that supports the services of Branches and Electronic Banking.

b)

When they generate an impact on the critical components of the Technological Infrastructure that has resulted in the total or partial activation of the Business Continuity Plan.

c)

When they generate an impact of 30% in their Branches; ATMs; Point of Sale Terminals or points of attention of their agents for scenarios different from impacts in the Technological Infrastructure, to which Annex 67 of these provisions refers.

The aforementioned notification must be made within sixty minutes following the update of any of the aforementioned criteria, and must include the date and time of the start of the Operational Contingency; the indication of whether it continues or, if applicable, if it has concluded and its duration; the affected processes, systems, and channels; a description of the event that has been registered, and an initial evaluation of the impact or gravity. The Institution must communicate daily to the Commission, through the means indicated in the first paragraph of this fraction, the status of the Operational Contingency until such time as it is concluded, and, regarding the last communication, must include the date and time when it is determined that it has concluded and its total duration.

Likewise, the general manager must send to the Commission, within a period not exceeding 15 business days following the conclusion of the Operational Contingency, an analysis of the causes that motivated it, the impact caused in qualitative and quantitative terms that includes, at least, the temporality, the monetary impact breaking down the detail of costs, and the indication of the actions that will be implemented to minimize damage in similar subsequent situations, including the work plan that is elaborated for this purpose, which must contain at least the personnel responsible for its design, implementation, execution, and monitoring, deadlines for its execution, detail of activities performed and to be performed, as well as the technical, material, and human resources employed.

... "

" Article 166 .- . . .

I. and II.

...

III.

Promote the correct functioning of the Technological Infrastructure in accordance with the security measures referred to in Article 168 Bis 11 of these provisions, assisting for such effect with the chief information security officer referred to in Article 168 Bis 14 of these provisions, as well as the elaboration of complete, correct, precise, integral, reliable, and timely information, including that which must be provided to competent authorities, and which contributes to adequate decision-making.

IV.

...

V.

Is repealed.

Last paragraph.- Repealed.

" Section Eighth Bis

On Information Security

Article 168 Bis 11.- The general manager of the Institution will be responsible for the implementation of the Internal Control System in matters of information security that ensures its confidentiality, integrity, and availability. The management framework referred to in this paragraph must ensure that the Technological Infrastructure, whether owned or provided by third parties, adheres to the following requirements:

I.

That each of its components performs the functions for which it was designed, developed, or acquired.

II.

That its processes, functionalities, and configurations, including its development or acquisition methodology, as well as the record of its changes, updates, and the detailed inventory of each component of the Technological Infrastructure, are documented.

III.

That information security aspects have been considered in the definition of projects to acquire or develop each of its components, including them during the various stages of the lifecycle. This will comprise the elaboration of requirements, design, development or acquisition, implementation testing, acceptance testing by Users of the Technological Infrastructure, release processes including vulnerability testing and code analysis prior to production, periodic testing, change management, replacement, and destruction of information.

In the case of communications and computing components, security aspects must include, at least, the following:

a)

Logical segregation, or logical and physical segregation of different networks in different domains and subnets, depending on the function they perform or the type of data transmitted, including segregation of production environments from development and testing environments, as well as perimeter and network security components that ensure that only authorized traffic is permitted. In particular, in those segments with links to the outside, such as the Internet, providers, authorities, other networks of the Institution or headquarters, and other third parties, all of this referred to critical services, whether payment systems, encryption equipment, operation authorizers, among others, consider safe zones, including those known as demilitarized zones (DMZ).

b)

Secure configuration according to the type of component, considering at least, ports and services, permissions granted under the principle of least privilege, use of removable storage media, access lists, manufacturer updates, and reconfiguration of factory parameters. The principle of least privilege will be understood as the enabling of access only to the information and resources necessary for the development of the functions of each User of the Technological Infrastructure.

IV.

That each of its components is tested before being implemented or modified, using quality control mechanisms that prevent the use of real data from the production environment, the disclosure of confidential or security information, or the introduction of any functionality not recognized for said component.

V.

That it has the licenses or use authorizations, if applicable.

VI.

That it has security measures for its protection, as well as for the access and use of the information that is received, generated, transmitted, stored, and processed in the own Technological Infrastructure, having at least the following:

a)

Identification and Authentication mechanisms for all and each of the Users of the Technological Infrastructure, which allow them to be recognized unequivocally and ensure access only to persons expressly authorized for this purpose, under the principle of least privilege.

For the foregoing, relevant controls must be included for those Users of the Technological Infrastructure with greater privileges, derived from their functions, such as those for database and operating system administration.

Likewise, policies and procedures must be provided for access authorizations by exception, such as users of development environments with access to production environments and access due to contingency events, among others. Such policies and procedures must be approved by the Chief Information Security Officer.

b)

Encryption of information according to the degree of sensitivity or classification that the Institution determines and establishes in its policies, when such information is transmitted, exchanged, and communicated between components, or stored in the Technological Infrastructure or accessed remotely.

c)

Access keys with composition characteristics that prevent unauthorized access, considering processes that ensure that only the User of the Technological Infrastructure knows them, as well as security measures, encryption in storage, and mechanisms to change access keys every 90 days or less. In the case of Users of the Technological Infrastructure assigned to applications or components to authenticate with each other, the change referred to in this subsection must be carried out at least once a year. In the event that any User of the Technological Infrastructure has knowledge of the access keys and ceases to provide their services to the Institution, these must be modified immediately.

d)

Controls to automatically terminate unattended sessions, as well as to prevent unauthorized simultaneous sessions with the same User of the Technological Infrastructure identifier.

e)

Security mechanisms, both physical access and environmental and electrical energy controls, that protect the Technological Infrastructure and allow operation in accordance with the specifications of the provider, manufacturer, or developer.

f)

Validation measures to guarantee the authenticity of transactions executed by the different components of the Technological Infrastructure, considering, at least, the following:

The truthfulness and integrity of the information.

Authentication between components of the Technological Infrastructure, which ensure that only legitimate service requests are executed from their origin to their execution and registration.

Messaging, communication, and encryption protocols, which must ensure the integrity and confidentiality of the information.

The identification of atypical transactions, anticipating that applications will have automatic alert measures for attention by the corresponding operational areas.

The update and maintenance of digital certificates and components provided by service providers that are integrated into the transaction execution process.

The measures referred to in this subsection must be established in accordance with the degree of risk that the Institutions define for each type of transaction.

VII.

That it have backup mechanisms and information recovery procedures that mitigate the risk of operational interruption, in accordance with what is provided in Article 164 Bis of these provisions.

VIII.

That it maintain complete audit records, including detailed information of accesses or access attempts and the operation or activity carried out by Users of the Technological Infrastructure, this, regardless of the level of privileges they have for access, generation, or modification of the information they receive, generate, store, or transmit in each component of the Technological Infrastructure, including automated process activity, as well as procedures for the periodic review of such records.

Institutions must conserve the audit records referred to in this subsection for a period of three years when such records refer to activities carried out on components that process or store information considered as critical in accordance with the classification indicated in Article 86, subsection III, subsection b), numeral 3 of these provisions. Otherwise, the conservation period of the records will be a minimum of six months.

IX.

That for the attention of Information Security Incidents, there be management processes that ensure detection, classification, attention, and containment, investigation, and, if applicable, digital forensic analysis, diagnosis, reporting to competent hierarchical levels, solution, follow-up, and communication to authorities, clients, and counterparties of such incidents.

For the detection and response to Information Security Incidents referred to in the previous paragraph, the General Director must designate a team that incorporates personnel from the different areas of the Institution to participate in each activity of the management process mentioned above, of which, in any case, the Chief Information Security Officer must be a part in accordance with subsection VII of Article 168 Bis 14 of these provisions.

In the event that vulnerabilities and deficiencies in the Technological Infrastructure are detected, corrective actions or compensatory controls must be taken according to the level of risk involved, preventing Users of the Technological Infrastructure or the Institution from being affected.

X.

That it be subjected to annual planning and review exercises that allow measuring its capacity to support its operation, guaranteeing that the detected capacity increase needs resulting from such exercises are attended to promptly.

Likewise, the Institution must evaluate the obsolescence of the components of the Technological Infrastructure, having a plan for their update.

XI.

That it have automated controls or, in their absence, compensatory controls, such as double verification, which prior to or subsequent to the operation in question, minimize the risk of elimination, exposure, alteration, or modification of information, derived from manual or semi-automated processes carried out by the Institution's personnel, with the objective of preventing errors, omissions, theft, or manipulation of information.

XII.

That it have controls that allow detecting the alteration or forgery of books, records, and digital documents related to the active, passive, and service operations of the Institution.

XIII.

That it have processes to measure and ensure availability levels and response times, which guarantee the execution of operations and services performed; this including scenarios where Institutions contract the provision of services by external providers for the processing and storage of information.

XIV.

That it have automated devices or mechanisms to detect and prevent events and Information Security Incidents, as well as to prevent unauthorized incoming or outgoing data connections and flows and information leakage, considering among others, removable storage media.

Institutions must correlate the data obtained from the automated devices or mechanisms referred to in the previous paragraph with data from other sources, such as activity records or Information Security Incidents.

Additionally, to what is stated in the previous paragraph, Institutions must maintain controls that prevent the leakage of information corresponding to the configuration of the Technological Infrastructure, such as IP addresses, firewall rules, as well as hardware and software versions.

XV.

That for the provision of information technology services to Users of the Technological Infrastructure, in their strategy, design, transition, operation, and continuous improvement phases, the integrity of the Technological Infrastructure as well as the integrity, confidentiality, and availability of the information received, generated, processed, stored, and transmitted by it be protected.

The General Director will be responsible for documenting in policies and procedures what is provided for in this article.

Article 168 Bis 12.- The General Director of the Institution will be responsible for compliance with the following obligations regarding the Technological Infrastructure:

I.

Approve the Security Master Plan, which must be aligned with the Institution's business strategy, as well as define and prioritize projects in the matter of information security, with the objective of reducing exposure to technological risks and the materialization of Information Security Incidents up to acceptable levels in the terms defined by the Board, based on an analysis of the current situation.

For the approval of said plan, the General Director must verify that it contains initiatives directed at improving existing work methods and may contemplate the required controls in accordance with applicable provisions.

The General Director must inform the Board of the content of the Security Master Plan, and have evidence of its implementation.

II.

Carry out security reviews, focused on verifying the sufficiency of controls applicable to the Technological Infrastructure. These reviews must comprise at least the following:

a)

Authentication Mechanisms of Users of the Technological Infrastructure.

b)

Configuration and access controls to the Technological Infrastructure.

c)

Updates required for operating systems and software in general, prior to their implementation and once implemented.

d)

Identification of possible unauthorized modifications to the original software.

e)

Devices, communication networks, systems, and processes associated with Electronic Means and public attention channels, in order to verify that there are no vulnerabilities or that there are tools or procedures that allow knowing the Authentication Credentials of Users of the Technological Infrastructure, as well as any information that directly or indirectly could give access to the Technological Infrastructure on behalf of the User of the Technological Infrastructure.

The reviews referred to in this subsection must be carried out, at least, once a year or before if significant changes occur in the Technological Infrastructure. To determine if it is a significant change, the opinion of the Chief Information Security Officer must be obtained for this purpose.

III.

Elaborate an annual calendar for the performance of vulnerability scanning tests of the components of the Technological Infrastructure that store, process, or transmit information, prioritizing them according to the result of the information classification exercise referred to in Article 86, subsection III, subsection b), numeral 3. The calendar must provide for the quarterly review of some of the components of the Technological Infrastructure so that by the end of the year, all components that store, process, or transmit information classified as critical have been reviewed, as well as those that the Institution considers necessary. The General Director will be responsible for monitoring that such tests are carried out either through the Institution itself or a third party hired for this purpose. Additionally, when new components of the Technological Infrastructure are incorporated, the General Director will be responsible for monitoring that the vulnerability scanning test is performed prior to their production deployment.

IV.

Hire an independent third party, with personnel who have verifiable technical capacity through specialized industry certifications in the matter, for the performance of penetration tests in the different systems and applications of the Institution with the purpose of detecting errors, vulnerabilities, unauthorized functionality, or any code that puts or may put at risk the information and assets of clients and the Institution itself. Such review must include the verification of the integrity of hardware and software components that allow detecting alterations to them. Such tests must consider, at least, the following:

a)

Their scope and methodology, which must be validated by the Chief Information Security Officer.

b)

To be carried out at least twice a year on different systems and applications, or when ordered by the Commission having detected factors that could affect the systems and applications or the information received, generated, processed, stored, or transmitted in them. In the latter case, the Commission will determine the scope of the tests, as well as the deadlines for carrying them out.

Additional tests may be carried out at the discretion of the General Director, with the opinion of the Chief Information Security Officer, when there are significant changes in the systems and applications, or to perform them on previously reviewed systems and applications when there are critical vulnerabilities.

The General Director of the Institution must send to the Commission, within 20 business days of having finalized the tests, a report with the conclusions of these. In the submission made, care must be taken to use mechanisms that prevent access to the content of this report by unauthorized personnel.

V.

Classify the detected vulnerabilities according to the methodology approved by the risk committee.

VI.

Elaborate remediation plans regarding the findings of the reviews and tests referred to in subsections II, III, and IV above, considering the classification of subsection V of this article, as well as implementing defense mechanisms that prevent unauthorized access and use of the Technological Infrastructure.

The remediation plans referred to in the previous paragraph must be validated by the Chief Information Security Officer. Likewise, such plans must contain, at least, the indication of the personnel responsible for their implementation and execution, as well as the deadlines for this, detail of activities carried out and to be carried out, as well as the technical, material, and human resources employed. The aforementioned remediation plans must be elaborated once the vulnerabilities are identified and sent to the Commission within a period of 10 business days.

In addition to what is stated in the previous paragraph, in the case of short, medium, or long-term projects in the remediation plans, they must be incorporated into the Security Master Plan.

VII.

Implement follow-up processes for compliance with the aforementioned remediation plans, which must be verified by the Chief Information Security Officer.

VIII.

Implement the annual training programs referred to in subsection V of Article 69 of these provisions, as well as those on awareness in the matter of information security, directed to all personnel and clients including, if applicable, third parties who provide services to them, in which, among other aspects, the roles and responsibilities that Users of the Technological Infrastructure have in this regard are contemplated.

IX.

Proactively and iteratively search for fraud alerts, as well as threats, such as phishing email campaigns, fake websites, disclosure of databases with Public User information, alteration of ATMs or point-of-sale terminals, and identity theft, among others, that could affect the information security of the Public User, as well as actions for their protection considering, at least, the following:

a)

The continuous investigation, collection, processing, and analysis of information that comes from any source related to the products and services offered by the Institution, which may constitute indications or evidence that security controls have been evaded, representing a threat to the information or resources of the Public User.

The indications or evidence referred to in the previous paragraph will be kept in a record which must be contained in the database referred to in the first paragraph of Article 168 Bis 17 of these provisions.

b)

The implementation of proactive processes to protect the information or resources of clients when the indications or evidence mentioned in subsection a) above occur, such as blocking and replacement of disposal means, change of authentication data, and notifications, among others.

c)

That it have communication procedures and security recommendations with affected clients, to inform them about the remediation processes that the Institution will carry out and, if applicable, the measures that the client themselves must adopt, such as changing passwords, verifying balances and transactions, installing antivirus, installing malware detection software, reviewing devices, and reinstalling applications, among others.

The terms and conditions for carrying out the processes by which the activities mentioned in this subsection are carried out must be documented in the respective policy and procedure manuals, in which it must be provided that the Institution will maintain evidence of the carrying out of such activities.

X.

Implement controls that allow the Institution to ensure the confidentiality, integrity, and availability of the Public User's information and the Institution's own information or access to the Technological Infrastructure, by its employees or personnel who have access to it, which guarantee that such information and Technological Infrastructure are not altered or cause an impact on the Institution or on its clients' resources. Such controls must be implemented from the respective hiring until their termination.

Article 168 Bis 13.- Institutions must have a person who serves as Chief Information Security Officer, known as CISO by its English acronym (Chief Information Security Officer).

The Chief Information Security Officer must be designated by the General Director and occupy the level immediately below that of the General Director, reporting directly to them. They will be responsible for information security matters of the Institution and must respond to requirements formulated by authorities and within the Institution in said matter.

The Chief Information Security Officer must not have conflicts of interest regarding areas of information technology, audit, and Business Units within the Institution and cannot perform the functions of the persons in charge of the implementation and operation of the information security of the Institution itself.

Article 168 Bis 14.- The Chief Information Security Officer of the Institutions must:

I.

Participate in the definition and verify the implementation and continuous compliance of the security policies and procedures indicated in Article 168 Bis 11 of these provisions.

II.

Elaborate the Security Master Plan, which must contain, for each project defined, the project name, objective, scope, start and end dates, involved areas, and projected investment. The scope must include, among others, the magnitude of the works.

III.

Verify at least annually, the definition of access profiles to the Institution's Technological Infrastructure, whether own or provided by third parties, according to job profiles (functional segregation), including those with high privileges such as operating system, database, and application administration.

IV.

Ensure at least annually or earlier in the event of an Information Security Incident, the correct assignment of access profiles to Users of the Technological Infrastructure. The function referred to in this subsection may be carried out through representative and random samples.

Likewise, they will be responsible for the temporary authorization of access by exception, such as those of users of development environments with access to production environments, access due to contingency events, or any other privileged access that does not correspond to the policy determined by the Institution. Likewise, they must have a record containing the name of the User of the Technological Infrastructure, associated application, environment, reason for the exception, and start and end date of the assignment.

V.

Approve and verify compliance with the measures that have been adopted to remedy deficiencies detected as a result of the functions referred to in subsections III and IV of this article, as well as the findings of both internal and external audits related to the Technological Infrastructure and information security.

VI.

Manage information security alerts communicated by the Commission or other means, as well as Information Security Incidents, considering the stages of identification, protection, detection, response, and recovery.

VII.

Coordinate and preside over the team for the detection and response to Information Security Incidents within the Institution.

VIII.

Inform the Audit Committee and the Institution's risk committee or the Committees designated for this purpose, in the session immediately following the verification of the Information Security Incident in question, regarding the actions taken and the follow-up to measures to prevent or avoid the recurrence of the aforementioned incidents.

IX.

Validate the definition of the security mechanisms mentioned in Annex 71 of these provisions, as well as verify their compliance.

X.

Propose and coordinate the training and awareness programs in the matter of information security within the Institution and towards the Public User, and verify their effectiveness.

XI.

Present monthly to the General Director the management report in the matter of information security. This report must be made to the other committees or Board, as determined by the General Director or at their request.

XII.

Regarding the indicators referred to in numeral 7 of subsection a) of subsection III of Article 86 of these provisions, in the matter of information security, they must consider as

risk indicators at least those established in Annex 72 of these provisions, and report the result of the evaluation of said indicators to the Board, as well as to the Audit Committee, Risk Committee, or the committee constituted by the Institution for such purposes.

XIII.

Be responsible for implementing the regulation on information security issued by other financial authorities.

Institutions must ensure that the Chief Information Security Officer has access to the records of persons who have access to information related to the operations in which the Institution itself intervenes, including those located abroad and of the Users of the Technological Infrastructure who have high privileges, such as administration of operating systems and databases, as well as their service providers.

Institutions that belong to a financial group subject to the supervision of the Commission or that are part of Consortia or Business Groups that have a financial entity subject to the supervision of said Commission, may assign the functions of the Chief Information Security Officer to the person performing such activities in the financial entity supervised by the Commission, provided that such person complies with Article 168 Bis 13 of these provisions.

Article 168 Bis 15.- The Chief Information Security Officer of the Institutions may support the exercise of their functions with information security representatives from the different Business Units called operational information security officers, who will be responsible for the application of information security policies and processes in their respective Business Units, contributing to management processes, risk reporting, compliance evaluations, and security intelligence.

These operational officers will have the following functions:

I.

Verify the application of information security policies and procedures in their Business Unit, reporting on this management to the Chief Information Security Officer at least monthly.

II.

Report to the Chief Information Security Officer any risk or eventuality that could impact information security.

III.

Propose to the Chief Information Security Officer the adoption of additional information security controls.

Operational information security officers must stay updated regarding applicable regulations in this matter and may recommend to Business Unit personnel the adoption of information security measures that have previously been authorized by the Chief Information Security Officer.

Article 168 Bis 16.- In the event that an Information Security Incident occurs that meets any of the requirements referred to in paragraphs a) to d) of fraction I of this article in: (i) the components of the Institution's Technological Infrastructure; (ii) customer service channels, such as Electronic Media, Bank Offices, or Institution commissionaires; or (iii) the technological infrastructure of any third party that affects the operation or the Institution's Technological Infrastructure, the General Manager of the Institution must:

I.

Provide for the necessary measures to inform the Commission immediately of Information Security Incidents, via email sent to the account Ciberseguridad- CNBV@cnbv.gob.mx or through other means indicated by said Commission, generating an electronic receipt. In such notification, at least the date and time of the start of the Information Security Incident in question must be indicated, and, if applicable, whether it continues or has concluded and its duration; a description of said incident, as well as an initial assessment of the impact or severity.

The Information Security Incidents that must be reported immediately are those that update at least one of the following scenarios:

a)

It generates economic loss, information loss, or interruption of the Institution's services.

b)

Its mode of operation, including exploited vulnerabilities, could be replicated in other Institutions.

c)

It could represent an impact on the Institution's clients, the stability of the financial or payment system, or on central payment systems, their service providers, clearing houses, or securities depository institutions.

d)

Any other considered serious at the Institution's judgment.

Additionally, Institutions must send via email to the Commission at the account Ciberseguridad-CNBV@cnbv.gob.mx or through other means indicated by said Commission, within 5 business days following the identification of the Information Security Incident in question, the information contained in Annexes 64 and 64 Bis of these provisions.

Institutions must conserve and keep available to the Commission, for the period indicated in Article 168 Bis 17 of these provisions, the records of Information Security Incidents that do not meet any of the characteristics mentioned in the previous paragraphs.

II.

Carry out an immediate investigation into the causes that generated the Information Security Incident and establish a work plan describing the actions to be implemented to eliminate or mitigate the risks and vulnerabilities that facilitated the mentioned incident. This plan must indicate, at least, the personnel responsible for its design, implementation, execution, and monitoring, deadlines for execution, as well as technical, material, and human resources, and must be sent to the Commission within a period not exceeding 15 business days after the Information Security Incident concluded.

When the Information Security Incident refers to Sensitive Information in the custody of the Institution or third-party service providers being extracted, lost, deleted, altered, or if Institutions suspect any act involving unauthorized access to such information, the General Manager or the person they designate must notify clients of the possible loss, extraction, alteration, loss, or unauthorized access to their information, within the following 48 hours from when the Information Security Incident occurred or was known, through the notification means the client has indicated for such effect, in order to prevent them from risks derived from the misuse of information that has been extracted, lost, deleted, or altered, informing them of the measures they must take and, if applicable, the replacement of corresponding disposal means or the substitution of necessary Authentication Factors. The evidence of this notification must be included in the result of the investigation mentioned in the previous paragraph.

Article 168 Bis 17.- Institutions must keep a database record of incidents, failures, or vulnerabilities detected in the Technological Infrastructure, which must include at least information related to the detection of failures, operational errors, attempts at computer attacks and those effectively carried out, as well as loss, extraction, alteration, loss, or misuse of information of Technological Infrastructure Users, where the date of the event and a brief description of it, its duration, affected service or channel, affected clients and amounts, as well as corrective measures implemented are contemplated.

The information referred to in this article must be backed up in the means determined by the Institutions and conserved for at least 10 years. "

" Article 169.- Institutions must document in manuals the policies and procedures related to the operations of their object, including those related to the functioning of their Technological Infrastructure, which must be consistent with the objectives and guidelines of the Internal Control System, as well as describe the functions of the Institution's Internal Audit.

. . . "

" Article 315 Bis.- . . .

I.

Ordering clients must register instructions for payment of the order indicating beneficiary data, including full name, date of birth, and Mobile Phone Number. Likewise, the individualized amount assigned to each of them must be indicated, which cannot exceed the equivalent in national currency to Medium-Value Monetary Operations.

II. to V.

. . .

. . . "

" Article 316 Bis 10 .- . . .

I. to IV.

. . .

V.

Regarding the Electronic Banking service using debit and credit cards, with the certifications indicated below:

a)

Certifications of security standards of the card industry, including among others: the data security standard (PCI-DSS), the data security standard for payment applications (PA-DSS), and security requirements and PIN transactions (PTS) or their equivalents or those that, in the Commission's judgment, allow the proper protection of stored, transmitted, or processed information.

b)

Certification according to the interoperability standard for debit and credit cards known as EMV, levels 1 (interfaces, physical, electrical, and transport) and 2 (payment application selection and transaction processing), if applicable, those other standards that, in the Commission's judgment, satisfy this requirement and allow adequate interoperability. The foregoing only applies to Access Devices for Integrated Circuit Card Banking operations where the information to perform operations is taken directly from the integrated circuit of the card. "

" Article 316 Bis 12.- Repealed. "

" Article 316 Bis 14.- Institutions must keep in databases all operations carried out through the Electronic Banking service that are not recognized by their Users and that, at least, include information related to operations not recognized by Users and the procedure that, if applicable, the User has promoted, such as claim folio, claim date, cause or reason for the claim, operation date, source account, product type, Electronic Banking service in which the operation was made, amount, status of the claim, resolution, resolution date, amount credited, amount recovered, and amount lost.

. . . "

" Article 316 Bis 17.- Repealed. "

" Article 316 Bis 20.- Repealed. "

TRANSITIONAL PROVISIONS

FIRST.- This Resolution will enter into force the day following its publication in the Official Journal of the Federation, except for what is provided in the following transitional articles.

SECOND.- The norms contained in Article 86, fraction III, paragraph b), numeral 3, which is amended, and 168 Bis 11 fractions II, III paragraph b), IV, VI, paragraphs b) to e), IX, last paragraph; 168 Bis 12 fractions II, III, VIII and 168 Bis 14, fraction VI, which are added by this Resolution, will enter into force six months after their publication in the Official Journal of the Federation.

The obligations of Article 168 Bis 11, regarding the technological infrastructure requirements, as defined in this Resolution, provided by third parties contracted by credit institutions prior to the entry into force of this instrument, must be complied with within a maximum period of three years counted from the entry into force of this Resolution or at the time of renewal of the respective contract, whichever occurs first. Contracts with third parties made by credit institutions for the provision of technological infrastructure, contracted from the start of the validity of this Resolution, must comply with the requirements of Article 168 Bis 11, within six months counted from the entry into force of this instrument.

THIRD.- The obligations contained in Articles 168 Bis 11 fractions VI, paragraph a), X, XIII, XV; 168 Bis 12 fractions I, V; 168 Bis 13; 168 Bis 14 fractions I, II, IV second paragraph, VII, VIII, XI, XII, XIII and second paragraph of said article, which are added by this Resolution, will enter into force nine months after their publication in the Official Journal of the Federation.

The institutions referred to in Article 2, fraction II, of the Credit Institutions Law, must make the designation referred to in Article 168 Bis 13, twelve months after its publication in the Official Journal of the Federation.

Until the designation of the person mentioned in Article 168 Bis 13 of this Resolution is carried out, credit institutions will be obliged to carry out the respective functions through the person who, at the entry into force of this Resolution, is in charge of information security surveillance.

FOURTH.- The obligations contained in Articles 168 Bis 11 fractions VI, paragraph f), VIII, XI, XII, XIV first and second paragraphs; 168 Bis 12 fractions IV, VI, VII, IX and X; 168 Bis 14 fractions III, IV first paragraph, V, IX, X; as well as Article 316 Bis 10, fraction V regarding merchants and for the institutions themselves to provide for in the security master plan, as defined in this Resolution, which are added, will enter into force twelve months after their publication in the Official Journal of the Federation.

FIFTH.- The obligation contained in Article 168 Bis 11, fraction III, paragraph a), which is added by this Resolution, will enter into force eighteen months after its publication in the Official Journal of the Federation.

SIXTH.- The norms contained in Articles 15 Bis, fraction VI, paragraph c); 164, fraction VI, paragraphs b) and c); and 316 Bis 17, will be repealed six months after the publication in the Official Journal of the Federation of this Resolution.

SEVENTH.- The norms contained in Articles 15 Bis, fraction V, paragraph a) and 166, fraction V, will be repealed nine months after the publication in the Official Journal of the Federation of this Resolution.

EIGHTH.- The norms contained in Articles 15 Bis, fraction V, paragraph d), 164, fraction V, paragraphs g) and h) and 316 Bis 20, will be repealed twelve months after the publication in the Official Journal of the Federation of this Resolution.

Sincerely,

Mexico City, November 15, 2018.- The President of the National Banking and Securities Commission, José Bernardo González Rosas.- Signature.

ANNEX 64

Incidents of Impact in Information Security

I.

Institution Information

a)

Name of the Institution.

b)

Full name of the Chief Information Security Officer, as well as their phone number and email address.

II.

Detailed Information of the Information Security Incident

Description of the Information Security Incident

a)

Date and time it occurred

b)

Date and time it was detected

c)

Duration of the incident

d)

Location of the affected installation (data center, Bank Office)

e)

Is the information involved in the incident managed by third parties? Yes ( ) No ( )

f)

If the answer to paragraph e) is affirmative, detail provider data (name, address and contact data, email, phone, among others)

Impact Caused by the Information Security Incident

g)

Can the incident cause monetary loss for customers or for the institution itself? Yes ( ) No ( )

h)

Is it viable to recover direct (own management) or indirect (through insurance) the possible monetary loss, through other institutions or financial entities? Yes ( ) No ( )

i)

Have other incidents related to the one reported been identified, whether by origin, mode of operation or impact? Yes ( ) No ( )

j)

Indicate, if applicable, the type of information compromised with the Information Security Incident, according to the following tables:

Compromised Client Personal Information

Names Yes ( ) No ( )

Addresses Yes ( ) No ( )

Phone Numbers Yes ( ) No ( )

Email Addresses Yes ( ) No ( )

Biometric data (fingerprints, iris or retina patterns or facial recognition, among others) Yes ( ) No ( )

Other(s):

Account or Balance Information

Debit, credit or other card numbers Yes ( ) No ( )

Account Numbers Yes ( ) No ( )

Passwords or personal identification numbers Yes ( ) No ( )

User Identifiers Yes ( ) No ( )

Credit Limits Yes ( ) No ( )

Balances Yes ( ) No ( )

Other(s)

Institution Information

Access Keys Yes ( ) No ( )

Security Configurations Yes ( ) No ( )

Port or Service Identification Yes ( ) No ( )

IP Addresses of components or services Yes ( ) No ( )

IP Addresses of internal components Yes ( ) No ( )

Access to internal network segments Yes ( ) No ( )

Software versions, operating systems or databases Yes ( ) No ( )

Vulnerability Identification Yes ( ) No ( )

Other(s)

III.

Classify the reported Information Security Incident based on the following definitions:

Class of Information Security Incidents

a) Physical Attacks

Sabotage Yes ( ) No ( )

Vandalism Yes ( ) No ( )

Theft of devices Yes ( ) No ( )

Information leak in physical media Yes ( ) No ( )

Unauthorized physical access Yes ( ) No ( )

Coercion Yes ( ) No ( )

Extortion Yes ( ) No ( )

Terrorist attack Yes ( ) No ( )

Other(s):

b) Unintentional or accidental damage, information loss or asset loss

Improperly shared information Yes ( ) No ( )

Errors or omissions in systems or devices Yes ( ) No ( )

Errors in procedures or controls Yes ( ) No ( )

Unauthorized changes to data Yes ( ) No ( )

Loss of information or devices Yes ( ) No ( )

Other(s):

c) Incidents due to natural or environmental disasters

Earthquakes Yes ( ) No ( )

Floods Yes ( ) No ( )

Hurricanes Yes ( ) No ( )

Fires Yes ( ) No ( )

Radiation Yes ( ) No ( )

Corrosions Yes ( ) No ( )

Explosions Yes ( ) No ( )

Other(s):

d) Incidents due to failures or malfunctions

Devices Yes ( ) No ( )

Systems Yes ( ) No ( )

Communications Yes ( ) No ( )

Services Yes ( ) No ( )

Third-party equipment Yes ( ) No ( )

Supply chain Yes ( ) No ( )

Other(s):

e) Incidents due to interruption or lack of supplies

Absence of personnel Yes ( ) No ( )

Strikes Yes ( ) No ( )

Energy Yes ( ) No ( )

Water Yes ( ) No ( )

Telecommunications Yes ( ) No ( )

Other(s):

f) Incidents due to data interception

Espionage Yes ( ) No ( )

Messages Yes ( ) No ( )

Wardriving Yes ( ) No ( )

Man-in-the-middle attacks Yes ( ) No ( )

Session hijacking Yes ( ) No ( )

Sniffers Yes ( ) No ( )

Messaging theft Yes ( ) No ( )

Other(s):

g) Incidents due to malicious activity to take control, destabilize or damage a computer system

Identity theft Yes ( ) No ( )

Phishing Yes ( ) No ( )

Denial of service (DOS, DDOS) Yes ( ) No ( )

Malicious code (malware, trojans, worms, code injection, virus, ransomware) Yes ( ) No ( )

Social engineering Yes ( ) No ( )

Certificate violation (site spoofing, fake certificates) Yes ( ) No ( )

Hardware manipulation (anonymous proxies, skimmers, installation of sniffers) Yes ( ) No ( )

Information alteration (address spoofing and routing tables, DNS poisoning, configuration alteration) Yes ( ) No ( )

Abuse of information security review tools Yes ( ) No ( )

Brute force attacks Yes ( ) No ( )

Abuse of authorizations Yes ( ) No ( )

Organized crime Yes ( ) No ( )

Hacktivists Yes ( ) No ( )

Government or affiliated groups Yes ( ) No ( )

Terrorists Yes ( ) No ( )

Insiders Yes ( ) No ( )

Other(s):

h) Incidents originating from legal aspects

Violation of contractual clauses Yes ( ) No ( )

Violation of confidentiality agreements Yes ( ) No ( )

Adverse decisions (judicial resolutions in the same jurisdiction or in others) Yes ( ) No ( )

Other(s):

i)

Others (specify)

IV.

Indicate in the following tables the classification in which the incident is located using the concepts from the following catalog:

Specify which of the following categories the incident falls into:

Incident Type Catalog

Key Type

1 Cybersecurity ( )

2 Identity Spoofing ( )

3 Assault/Theft ( )

4 Physical Intrusion ( )

5 Information Loss ( )

999 Other ( )

Indicate the business line(s) affected by the incident:

Business Line Catalog

Key Product

101 Commercial Credits ( )

102 Consumer Credits ( )

103 Housing Credits ( )

104 Credit Cards ( )

105 Currencies ( )

106 Derivatives ( )

107 Repo ( )

108 SPEI/SPID/SWIFT ( )

109 Securities and Investment Instruments ( )

110 Savings, checking, etc. accounts ( )

112 Non-Banking Products ( )

199 Other ( )

Indicate the channels affected by the incident:

Affected Channel Catalog

Key Channel

201 Internet Operations Individuals ( )

202 Internet Operations Legal Entities ( )

203 E-commerce ( )

204 Telephone Banking ( )

205 Telephone Commerce ( )

206 ATMs ( )

207 Point of Sale Terminal ( )

208 Branches ( )

209 Correspondents ( )

210 Mobile Payment ( )

211 Mobile Banking ( )

212 Movement generated by the Bank ( )

213 Other Banks ( )

299 Other ( )

Indicate the type of asset affected by the incident:

Affected Asset Catalog

Key Impacted Asset

301 Statements ( )

302 Card Plastics ( )

303 Checkbooks ( )

304 PINs ( )

305 Passwords ( )

306 Databases ( )

307 TOKEN ( )

399 Other ( )

Name and signature of the Chief Information Security Officer

ANNEX 64 Bis

Information Security Incident Report

I.

Institution Information

a)

Name of the Institution.

b)

Full name of the Chief Information Security Officer, as well as their phone number and email address.

II.

Detailed Information of the Information Security Incident

a)

Attach the following information in encrypted digital media:


Description of the Information Security Incident.

Affected account numbers.

Status of affected accounts (blocked, suspended, active).

Affected network zone (internet, internal network, administration network, among others).

Type of affected system (file server, web server, email service, database, workstations, whether desktop or mobile, among others).

Operating system (specify version).

Protocols or services of the impacted components.

Number of components of the Institution's systems affected.

Applications involved (specify version).

Information on the compromised device, if applicable (brand, software version, firmware, among others).

Impact on service (considering any disruption) caused by the Information Security Incident.

Amount of loss in pesos, if applicable.

Amount recovered in pesos, if applicable.

Status of the Information Security Incident (Resolved or Unresolved).

Indicate whether the Information Security Incident has been disclosed to any authority. If affirmative, indicate the authority and the date.

Public IP addresses, email addresses, or domains from which the attack originates.

The communication protocol used, if applicable.

The URL in case of websites involved.

The malware or signature detected.

Detail the actions taken to mitigate the Information Security Incident, mentioning the persons responsible for implementing said mitigation actions.

Description of the results of the mitigation actions.

Actions to minimize damage in similar subsequent situations.

Other information that you consider should be known to this Commission.

Name and signature of the Chief Information Security Officer

ANNEX 71

TECHNICAL REQUIREMENTS FOR THE CAPTURE OF FINGERPRINTS AND FACIAL RECOGNITION AS BIOMETRIC DATA

I. Fingerprint Capture

The fingerprint records made by Institutions will consist of an image capture of the papillary ridges of the fingers on a contrasting surface by pressure, from which biometric data are obtained. This capture must consider controls that ensure they are obtained directly from the person, avoiding the recording of fingerprints from impressions on any material intended to simulate another person's fingerprint (live fingerprint test).

The first fingerprint capture process must consist of registering, first, the ten fingerprints of the employees, executives, and officials of the Institutions who will be in charge of registering customers' fingerprints. Second, the aforementioned employees, executives, and officials will proceed to capture at least six fingerprints of the Institution's customers. For this purpose, Institutions must assist the or those responsible for Internal Audit functions to verify what is provided in this paragraph.

The fingerprint capture process must prevent an employee, executive, or official of the Institution from registering their own fingerprints in place of the customer's. Institutions must at all times guarantee the integrity of the stored or transmitted biometric information, as well as its conservation, availability, and the impossibility of manipulation of such information. For the purposes of what is provided in this paragraph, Institutions must comply with at least the following:

a)

Logically and physically segregate the Technological Infrastructure on which the biometric information databases are maintained, including the segmentation of the different networks involved.

b)

Securely configure equipment, according to the type of Technological Infrastructure element, ports, services, permissions, access lists, manufacturer updates, and factory configuration.

c)

Establish access controls and identification and authentication mechanisms for all and each of the Users of the Technological Infrastructure, which allow them to be recognized unequivocally and ensure access only to persons expressly authorized for this purpose. Both mechanisms must include specific controls for those Users of the Technological Infrastructure with greater privileges, derived from their functions, such as database and operating system administration, including audit logs on all accesses.

d)

Have encryption mechanisms for information when it is transmitted or stored.

e)

Conduct tests aimed at detecting vulnerabilities and threats, as well as penetration testing on the different elements of the Technological Infrastructure in order to implement defense mechanisms that prevent unauthorized access and use of information.

f)

Implement controls for information conservation, including those regarding the integrity of stored information, which allow identifying any changes to the original data, as well as secure conservation and deletion that avoid at all times that they can be known by unauthorized third parties.

Institutions must use fingerprint readers of at least two fingers per reading (dual devices) for the first fingerprint capture procedure for the integration of their databases.

For the fingerprint capture process, the minimum image requirements are as follows:

Scanner Resolution (points per inch)

Depth (pixels)

Minimum Dynamic Range (gray levels)

500

8 bits

200

Platform (software and hardware) operation parameters for fingerprint capture

The applications and devices used in the fingerprint capture process on a contrasting surface by pressure, in order to integrate a database with such information, must consider at least the following requirements:

PARAMETER

DECISION

OBSERVATION

First fingerprint capture

Captured Image

Type of capture

M

Flat live.

Number of fingers

M

10 for employees, executives, and officials.

6 for customers as a minimum.

This, except for the exception established in this annex.

Finger position

MP

Fingers must be placed in the center of the plate with respect to its horizon and parallel to the capture surface.

Capture angle

MP

Fingers must be placed at 90° with a rotation of ±10° with respect to the plate's horizon.

Movement during capture

MP

Avoid sliding of fingerprints on the plate at the time of capture, to avoid smudged images.

Visualization

MP

The operator must observe capture information in real time.

Segmentation

MP

Proven by NIST in the test called "Slap Seg II test".

Sequence

M

Validate that fingerprints of each finger are not repeated during the same capture process.

Deduplication

M

Validate that the fingerprints of the Institution's customers or employees are not previously registered in the database with the information of another customer or employee of the Institution.

Devices

Dual

M

Certified EFTS annex F FAP 45.

Decadactylar (4-4-2)

M

Certified EFTS annex F FAP 60.

Sequence review.

Image

M

Generates RAW.

Preview of the taken image.

Information to be obtained from the device

M

The serial number is mandatory.

Optionally, the device must have Firmware version, manufacturer, and model.

Operation

Assisted

M

Yes. Hierarchical fingerprint capture and at least one fingerprint of the operator must be recorded, who must be registered biometrically in the Institution.

Analysis of quality parameters

M

In accordance with NFIQ.

Cleaning

MP

Clean the plate before each fingerprint capture for optical readers.

Lighting

MP

For optical devices, avoid light sources on the capture device.

Recapture

M

In case of not obtaining the minimum quality parameters, at least 3 attempts per fingerprint.

Transmission

Compression of 500 points per inch images (ppi, by its English acronym)

M

Single compression from RAW image. WSQ maximum 10:1.

Decision: M->Mandatory O->Optional MP->Best practice

In case that the applications, processes, parameters, or devices used in fingerprint capture do not comply with the requirements of this annex, Institutions must submit them to the approval of the Commission. Notwithstanding the foregoing, regarding the capture of customers' fingerprints, in no case may it be less than six fingerprints, except for the exception provided in this annex.

Exception to fingerprint capture

In case that customers, employees, executives, and officials of the Institutions are permanently unable to imprint their fingerprints on the respective readers, it must be specified that it is not possible to capture the fingerprint image due to amputations, grafts, malformation, permanent injury, prosthesis, disease, among others.

In any case, the greatest number of fingerprints possible must be captured, making the corresponding annotations in the file.

Authentication using the Institution's own fingerprint database

For the process by which fingerprint reading is made for authentication (1-to-1 matching) of already registered customers, and its use as Authentication Factor Category 4, if applicable, the image capture requirements are as follows:

Scanner Resolution (points per inch)

Depth (pixels)

Minimum Dynamic Range (gray levels)

300

4 bits

12

500

8 bits

80

PARAMETER

DECISION

OBSERVATION

Authentication

Captured Image

Number of fingers

O

1 to 4 depending on the type of reader.

Any finger

O

Yes. The sample against all records of the user.

Recapture

O

Yes. A minimum of three attempts is suggested.

Devices

Mobile

M

Certified EFTS annex F or PIV FAP 30.

Dual

M

Certified EFTS annex F FAP 45.

Decadactylar (4-4-2)

M

Certified EFTS annex F FAP 60.

Unidactylar

O

PIV is recommended.

Transmission

Format

O

One of the following: Proprietary Format, RAW Format, compressed image with ANSI INCITS 378 or ISO/IEC 19794-2 standards.

Decision: M->Mandatory O->Optional MP->Best practice

II. Operational Guidelines for Facial Recognition

In case that Institutions determine to obtain any facial recognition element from their customers, the applications and devices used in the process of capturing facial elements must consider at least the following requirements:

PARAMETER

DECISION

OBSERVATION

Facial image capture

Captured Image

M

2D Full Frontal, 24 bits color, minimum distance between eyes 90 pixels.

Digital and photographic requirements

M

ISO 19794-5 standard section 7.3, 7.4, 8.3, and 8.4.

Posture

M

Must allow a rotation of at least ±5° frontal in any direction (up, down, left, right).

Expression

M

Neutral facial expression. Smiles, winks, etc. must be avoided.

Gaze at the camera lens (with the exception of physical impediments).

Lighting

M

Balanced and distributed in each part of the face.

To achieve natural skin tones and avoid red eyes.

Depth of Field

M

The central pose of the complete face will be in focus from the crown to the chin and from the nose to the ears.

Glasses

M

The use of frames of any type will not be allowed.

Accessories

M

Only medical accessories are allowed (no hats, nor accessories that cover the face).

Impediments for the capture

M

Closed eyes.

Hair covering the eyes or forehead.

Elements obstructing the forehead.

Facial Hair

M

It is allowed.

PARAMETER

DECISION

OBSERVATION

Background

O

A uniform light-colored background will be used that contrasts with the face and hair; pale gray or white is recommended.

Operation

M

Controlled lighting environment.

Assisted

M

Yes.

Segmentation and feature extraction

M

Crop according to ICAO standard. Automatic feature extraction by software.

Quality review

M

Automatic by software; the ICAO standard for image quality must be evaluated.

Authentication

Image Capture

O

Same as facial image capture.

Number of Images

O

One full frontal.

Decision: M->Mandatory O->Optional MP->Best practice

The process of capturing elements for facial recognition must prevent an employee, executive, or official of the Institution from registering their own characteristics in place of the customer's. For this purpose, prior to starting the capture of customer information, Institutions must ensure that the data of their employees, executives, and officials have been captured previously. For this, Institutions must assist the or those responsible for Internal Audit functions to verify what is provided in this paragraph.

III. GLOSSARY

ANSI: American National Standards Institute, of the United States of America.

Authentication: The Process by which the User's identity is verified with the biometric data of fingerprints or face that Institutions have previously obtained. This process implies searches for stored patterns of a single individual (1-to-1).

Deduplication: The specialized data compression technique used to avoid duplicate copies of these.

EFTS (by its English acronym Electronic Fingerprint Transmission Specifications): The specifications for the transmission of biometric information of the Federal Bureau of Investigation of the United States of America (FBI).

FAP (by its English acronym FingerPrint Acquisition Profile): It is a subdivision of the categories applied to devices for fingerprint acquisition based on dimensions, number of simultaneous fingers to capture, image quality. When accompanied by a number (30, 45, 60) this indicates the capture area in inches (45=1.6 x 1.5; 60=3.2 x 3.0, etc.).

ICAO: The standard for passport photographs issued by the International Civil Aviation Organisation.

INCITS (by its English acronym InterNational Committee for Information Technology Standards): The central forum of the United States of America, dedicated to the creation of standards for technological innovation.

ISO/IEC: The standard for information security published by the International Organization for Standardization and the International Electrotechnical Commission.

NFIQ:

NIST Fingerprint Image Quality.

The quality standards of fingerprint images defined by NIST.

NIST:

National Institute of Standards and Technology.

PIV: The standard defined by NIST for 1-to-1 fingerprint verification (comparison of a fingerprint against a record).

Plate: The capture surface of the fingerprint capture device.

RAW: The format of the raw (unprocessed) image capture of a fingerprint.

Segmentation: The process by which the fingerprint image of each finger is individualized, based on an image compressed with WSQ or a single RAW image obtained from the reader, to obtain up to four independent images, one for each finger.

Slap Seg II Test: The test that evaluates the precision with which the algorithm segments images in multi-finger captures.

WSQ (by its English acronym Wavelet Scalar Quantization): The standard created by the FBI that defines the format for the compression of fingerprint images.

ANNEX 72

Information Security Indicators

The Chief Information Security Officer of the Institution, in relation to the information security indicators referred to in fraction XII of Article 168 Bis 14, of these provisions, must:

Evaluate these indicators, which must comply with the thresholds contained in this annex for each indicator. In case of defining different thresholds, the reason must be documented, which must be aligned with the Institution's risk tolerance level.

Define remediation plans for those risks where the evaluation results yield values that are within the medium and high risk thresholds established in this annex or, if applicable, those defined by the Institution, provided that these are in a high threshold for at least two consecutive periods.

Provide continuous maintenance, whether to add, eliminate, or update the existing key risk and information security performance indicators, which must always be aligned with the Institution's strategy and the Institution's Information Security Master Plan.

Measure and evaluate their evolution with the periodicity indicated in the following tables, or earlier in case of unusual events.

In case that not all assumptions apply, indicate that they are not applicable and explain the reason.

The type, subtype, and sub-class of events in which each of the indicators listed below are classified, have their basis in Section II of Annex 12-A of these provisions:

Type

Definition

Sub Type

Sub Class of Events

Examples

I. Internal Fraud

Losses derived from any type of action aimed at defrauding, improperly appropriating goods, or well, bypassing regulations, laws or corporate policies (excluding diversity / discrimination events) in which at least one internal party to the Institution is involved.

1.1 Unauthorized Activities.

1.1.1 Undisclosed operations (intentional).

1.1.2 Unauthorized operations (with financial losses).

1.1.3 Incorrect valuation of positions (intentional).

Undisclosed operations;

unauthorized operations (with

financial

losses);

incorrect valuation

of positions, and

intentional omission

of regulations.

1.2 Internal Theft and Fraud.

1.2.1 Fraud / credit fraud / worthless deposits.

1.2.2 Extortion / embezzlement / theft.

1.2.3 Misappropriation

of assets.

1.2.4

Willful destruction of assets.

1.2.5

Internal Forgery.

1.2.6 Utilization

of bounced checks.

1.2.7

Smuggling.

1.2.8 Appropriation of

accounts, identity, among others.

1.2.9 Non-compliance / tax evasion (intentional).

1.2.10

Bribery.

1.2.11 Abuse of

insider information (not for the benefit of the company).

Theft;

embezzlement;

misappropriation;

destruction of

assets;

forgeries;

identity theft; and

bribes;

manipulation of

accounts.

1.3. Security of the

systems.

1.3.1 Breach of security systems.

1.3.2 Damage from cyber attacks.

1.3.3 Theft of

information (with financial losses).

1.3.4 Inappropriate

use of access keys and/or authorization levels.

Abuse and use of

privileged or

confidential information;

alteration of

computer applications; theft

of passwords, and

prohibited computer

accesses.

II. External Fraud

Losses derived from any type of action aimed at defrauding, improperly appropriating goods or bypassing the legislation, by a third party.

2.1 External Theft and Fraud.

2.1.1 Robbery / fraud / extortion / bribery.

2.1.2 External Forgery / Identity Impersonation.

2.1.3

Fraudulent use of checks.

2.1.4 Use and/or disclosure of

insider information.

2.1.5

Industrial Espionage.

2.1.6

Smuggling.

Forged or manipulated

documentation (checks,

transfers,

etc.); identity theft;

improper dispositions;

counterfeit coins;

damaged or

out of legal circulation banknotes; robberies in the

Institution's premises, in

internal mail, cash transports or in

postal packages, and improper use of

stolen, forged,

stolen or blacklisted cards.

2.2 Security of the Systems.

2.2.1 Breach of security systems.

2.2.2 Damage from cyber attacks.

2.2.3 Theft of

information (with financial losses).

2.2.4 Inappropriate

use of access keys and/or authorization levels.

Unauthorized computer access;

manipulation of

computer applications;

damage from cyber attacks, and

theft of

information.

VI. Incidents

in the Business and

Failures in the

Systems

Losses derived from incidents in

the business and from

system failures.

6.1 Systems

6.1.1 Hardware.

6.1.2 Software.

6.1.3

Telecommunications.

6.1.4

Interruption / incidents in the

supply.

Interruption /

incidents in the

supplies and

communication lines;

errors in the

computer programs;

failures

in hardware and

software;

sabotage;

business interruptions;

computer failures and

virus programming.

ID

Name

Description

Domain

Type

Sub Type

Sub Class of Events

Type of

Indicator

Period

Unit of Measurement

Calculation

Variable X

Variable Y

High Risk

Medium Risk

Low Risk

KRI0001

Incidents

via direct

attacks against the

internal systems.

Number of incidents

that have been

originated by attacks

towards the internal systems of the

Institution, in the period

established.

Logical attacks.

II. External Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Reactive.

Quarterly.

Quantity.

Variable X

Number of

identified incident

cases.

More than 1.

Equal to 1.

Equal to 0.

KRI0002

Cases of fraud

in Electronic Banking.

Percentage of cases

where fraud is identified,

that has been

originated by attacks

towards the electronic banking systems of the

Institution, in the period

established.

Logical attacks.

II. External Fraud

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Reactive.

Monthly.

Percentage.

(X/Y)*100

Number of

cases of

fraud in

electronic banking.

Number of

electronic banking

users

active.

More than

.01

%.

Between 0.005 %

and 0.01 %.

Less than

0.005 %.

KRI0003

Equipment of the

Technological Infrastructure

whose

security configuration

is managed.

Percentage of equipment

of Technological Infrastructure within the

platform and/or

process of review of

secure configuration standards,

with respect to the total of

the equipment of the

Institution during the

established period.

Compliance.

II. External Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Preventive.

Monthly.

Percentage.

(X/Y)*100

Number of

equipment within

the

platform or

process of

review of

secure configuration

standards.

Total number

of equipment.

Less than

85 %.

Entre 85 % and

95

%.

More than 95 %.

KRI0004

Level of

compliance with

secure configuration

of UNIX/Linux

servers.

Average percentage of

compliance level of UNIX/

Linux servers included

within the tool

and/or process of review

of secure configuration

standards.

Compliance.

II. External

Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Preventive.

Monthly.

Percentage

average.

Average(X)

% of

compliance

of the

secure

configuration

standard

of each of

the UNIX/Linux

Servers.

Less than

90 %.

Between 90 % and

95

%.

More than 95 %.

KRI0005

Users with

inadequate roles and

profiles.

Percentage of users

with inadequate profiles within

the applications of the

Institution, with respect

to the total number of users in

all applications

of the Institution.

Compliance.

I. Internal

Fraud

1.3. Security

of the

systems.

1.3.3 Theft of

information (with

financial losses).

1.3.4 Inadequate

use of access keys

and/or authorization

levels.

Corrective.

Semi-annually.

Percentage.

(X/Y)*100

Number of

users with

incorrect

profiles,

considering

all

applications.

Total number

of users

considering

all

applications.

More than 3

%.

Between 1% and 3 %.

Less than 1

%.

KRI0006

Applications without

roles and profiles.

Percentage of

applications that

do not have the capacity

for role and permission

profiling, or that

such profiles are not

implemented, this

with respect to the total

of applications.

Compliance.

I. Internal

Fraud.

1.3. Security

of the

systems.

1.3.3 Theft of

information (with

financial losses).

1.3.4 Inadequate

use of access keys

and/or authorization

levels.

Corrective.

Quarterly.

Percentage.

(X/Y)*100.

Number of

applications

without capacity

for

profiling,

or profiling not

implemented.

Total number

of

applications.

More than 5

%.

Between 2 % and 5 %.

Less than 2

%.

KRI0007

Information security

incidents in general

Total number of

incidents reported

during the established

period regarding

information security.

Information.

Applies to:

I. Internal

Fraud

II. External

Fraud

VI.

Business

Incidents

and System

Failures.

Apply to:

1.3. Security

of the

systems

2.2 Security

of the

Systems.

6.1 Systems.

Apply to:

1.3.1 Breach of

security systems

1.3.2 Damage from

cyber attacks.

1.3.3 Theft of

information (with

financial losses).

1.3.4 Inadequate

use of access keys

and/or authorization

levels.

2.2.1 Breach of

security systems.

2.2.2 Damage from

cyber attacks.

2.2.3 Theft of

information (with

financial losses).

2.2.4 Inadequate

use of access keys

and/or authorization

levels.

6.1.1 Hardware.

6.1.2 Software.

6.1.3

Telecommunications.

6.1.4 Interruption /

incidents in the

Supply

Reactive.

Monthly.

Quantity.

Variable X.

Number of

security

information

incidents.

More than 5.

From 2 to 5.

Less than 2.

KRI0008

Obsolete and/or

outdated technological

platforms

Percentage of

technological

platforms that are

on obsolete versions and/or

without support from

the manufacturer

Infrastructure

.

II. External

Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Corrective.

Semi-annual

Percentage.

(X/Y)*10.

Number of

technological

platforms

obsolete.

Total of

technological

platforms.

More than 5

%.

Between 2 % and 5 %.

Less than 2 %

KRI0009

System failures

related to the

automated teller

machine network.

Number of system failures

related to the automated

teller machine network

lasting more than

10 minutes.

Infrastructure

.

VI.

Business

Incidents

and System

Failures.

6.1 Systems.

6.1.4 Interruption /

incidents in the

Supply.

Reactive.

Monthly.

Quantity.

Variable X.

Number of

system

failures.

More than 1.

Equal to 1.

Equal to 0.

KRI0010

Security incidents

from vulnerabilities

of systems

provided by

providers

(third parties).

Percentage of

security incidents

caused by

vulnerabilities in

systems and

technological

infrastructure provided

by providers

(third parties) that

do not belong to the

institution's payroll,

reported during the

established period, with

respect to the total

of security incidents.

Infrastructure

.

II. External

Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

2.2.2 Damage from

cyber attacks.

2.2.3 Theft of

information (with

financial losses).

2.2.4 Inadequate

use of access keys

and/or authorization

levels.

Reactive.

Monthly.

Percentage.

(X/Y)*100.

Number of

security incidents

attributed to

vulnerabilities

in systems

provided by

providers

(third parties).

Total number

of security

incidents.

More than 5

%.

Between 0.1 % and

5

%.

Less than 0.1

%.

KRI0011

Pending critical

vulnerabilities to be corrected detected in

ethical hacking

tests.

Number of

vulnerabilities in the

information systems

that, according to the

ethical hacking tests,

are classified

as critical, which

have more than one month

of age from

their date of detection.

Infrastructure

.

II. External

Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Preventive.

Monthly.

Quantity.

Variable X.

Number of critical

vulnerabilities

pending to be corrected with

age of

more than one

month.

More than 2.

Between 1 and 2.

Equal to 0.

KRI0012

Unavailability

of IT systems.

Average percentage of

downtime of the

systems against

the total time of the

established period.

Infrastructure

.

VI.

Business

Incidents

and System

Failures.

6.1 Systems.

6.1.4 Interruption /

incidents in the

Supply.

Reactive.

Monthly.

Percentage

Average.

Average(X).

Average of

downtime of

IT systems.

More than

0.5

%.

Between 0.25 %

and

0.5 %.

Less than

0.25 %.

KRI0013

Unavailability

of online

banking.

Percentage of time

downtime against

the total time of the

electronic banking

system against

the month in question.

Infrastructure

.

VI.

Business

Incidents

and System

Failures.

6.1 Systems.

6.1.4 Interruption /

incidents in the

Supply.

Reactive.

Monthly.

Percentage.

(X/Y)*100.

Time of

downtime of

electronic banking.

Total time

established

for electronic

banking.

More than

0.25 %.

Between 0.15 %

and

0.25 %.

Less than

0.15 %.

KRI0014

Critical and high

priority incidents

in production

environments.

Percentage of

incidents classified

as critical and high

priority in production

environments with respect

to the total incidents in

production.

Infrastructure

.

II. External

Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Reactive.

Monthly.

Percentage.

(X/Y)*100.

Number of

incidents in

production

classified

as critical.

Total number

of incidents

in production.

Greater than or

equal to

0.5

%.

Greater than 0% and

less than 0.5 %.

Equal to 0 %.

KRI0015

Components of the

technological

infrastructure

exposed to

the internet without

ethical hacking

tests and/or

vulnerability

analysis.

Percentage of the

components of the

technological

infrastructure of the

organization exposed to the internet to

which ethical hacking has not

been performed or

vulnerability

analysis, with

respect to the total

of equipment in more than 3

months.

Infrastructure

.

II. External

Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Corrective.

Quarterly.

Percentage.

(X/Y)*100.

Number of

assets

exposed to

the internet that have not

performed

ethical hacking tests or

vulnerability

analysis

.

Number of

assets

exposed to

the internet.

More than 3

%.

Between 1 % and 3

%.

Less than 1

%.

KRI0016

Pending critical

vulnerabilities to be corrected detected in the

vulnerability

analyses.

Number of

vulnerabilities in the

information systems

that, according to the

vulnerability

analyses, are

classified as

critical, which,

have more than one month

of age from

their date of detection.

Infrastructure

.

II. External

Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Corrective.

Monthly.

Quantity.

Variable X.

Total number of

critical

vulnerabilities.

More than 2

Between 1 and 2

Equal to 0

KRI0017

Fraud cases

reported by

electronic banking

clients.

Percentage of fraud cases

reported by

clients of the electronic

banking of the

Institution,

considering the number

total of electronic banking

clients in the

established period.

Infrastructure

.

II. External

Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Reactive.

Monthly.

Percentage.

(X/Y)*100.

Number of cases

of fraud

reported in

electronic

banking.

Number of

clients of

electronic

banking.

More than

0.005 %

Between 0.003 % and

0.005 %

Less than 0.003

%

KRI0018

Obsolete and/or

unsupported

Technological

Infrastructure.

Number of equipment and

Technological

Infrastructure, that are

on obsolete versions or

without support, in

comparison with all

active IT

infrastructure in the

established period.

Infrastructure

.

II. External

Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Corrective.

Quarterly.

Percentage.

(X/Y)*100.

Number of

equipment and

obsolete

infrastructure.

Total number

of active

equipment.

More than 5

%.

Between 2 % and 5 %.

Less than 2

%.

KRI0019

Servers without

antimalware

solution.

Percentage of

servers without

antimalware with respect to the total number of servers.

Malware.

II. External

Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Corrective.

Monthly.

Percentage.

(X/Y)*100.

Number of

servers without

antimalware.

Total number

of servers.

More than 6

%.

Between 3% and 6 %.

Less than 3 %.

KRI0020

Servers with

antimalware

signatures

outdated.

Percentage of

servers with

antimalware signatures

(malware signatures)

outdated

with respect to the total

of servers with

antimalware in each

Institution

Malware.

II. External

Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Corrective.

Monthly.

Percentage.

(X/Y)*100.

Number of

servers with

antimalware

signatures

outdated.

Total number

of servers

with

antimalware.

More than 6 %

Between 3% and 6 %

Less than 3 %

KRI0021

Workstations without

antimalware

solution

Percentage of

workstations without

antimalware with

respect to the total

equipment

Malware.

II. External

Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Corrective.

Monthly.

Percentage.

(X/Y)*100.

Number of

workstations without

antimalware.

Total number of

workstations.

More than 8

%.

Between 4% and 8 %.

Less than 4 %.

KRI0022

Workstations with

outdated

antimalware

signatures.

Percentage of

workstations that

have outdated

antimalware

signatures

(malware signatures)

with respect to the total

of computing equipment with

antimalware installed.

Malware.

II. External

Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Corrective.

Monthly.

Percentage.

(X/Y)*100.

Number of

workstations with

antimalware

signatures

outdated.

Number of

workstations

with

antimalware.

More than 8

%.

Between 4% and 8 %.

Less than 4 %.

KRI0023

Security incidents

attributed to

provider

personnel

(third parties).

Percentage of

security incidents

related to personnel

of providers

(third parties) that

do not belong to the

Institution's payroll,

reported during the

established period, with

respect to the total

of security incidents.

Incidents.

II. External

Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Reactive.

Monthly.

Percentage.

(X/Y)*100.

Number of

security incidents

related to

provider

personnel

(third parties).

Number of

total security incidents

of provider

personnel

(third parties).

More than 5

%.

Greater than 0 % and

less than 5 %.

Equal to 0 %.

KRI0024

Servers with

obsolete operating

system

versions.

Total percentage of

servers with

obsolete operating system

versions compared against

total number of

servers.

Software.

II. External

Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Corrective.

Monthly.

Percentage.

(X/Y)*100.

Number of

servers with

obsolete operating system

versions.

Total number

of servers.

More than

10

%.

Between 5% and 10 %.

Less than 5 %.

KRI0025

Production applications

with partial or

deficient compliance

of security

controls.

Percentage of

applications in

production with

partial or

deficient compliance,

with respect to

established security

policies,

in matters of

security, with respect

to the total number of applications.

Software.

II. External

Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Corrective.

Quarterly.

Percentage.

(X/Y)*100.

Number of

security controls

deficient in

applications in

production.

Total number

of security

controls.

More than 5 %.

Between 2 % and 5 %.

Less than 2 %.

KRI0026

Database managers (DBM)

with obsolete or

unsupported technology

versions.

Percentage of database managers (DBM),

which are versions of

obsolete technologies or not

supported by the

manufacturer, in

comparison with the total

of database managers

(DBM) active in the

established period.

Software.

II. External

Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Corrective.

Quarterly.

Percentage.

(X/Y)*100.

Number of database

managers

(DBM) obsolete

or unsupported.

Total number

database

managers

(DBM).

More than

10

%.

Between 5 % and 10

%.

Less than 5

%.

KRI0027

Obsolete or

unsupported

applications.

Percentage of

applications within

the Institution, which

are obsolete

or without support from

the manufacturer, in relation

to all active applications

during the

established period.

Software.

II. External

Fraud.

VI.

Business

Incidents

and System

Failures.

2.2 Security

of the

Systems.

6.1 Systems.

2.2.1 Breach of

security systems.

6.1.2 Software.

Corrective.

Quarterly.

Percentage.

(X/Y)*100.

Number of

obsolete or

unsupported

applications.

Total of

active

applications.

More than 5 %.

Between 2 % and 5 %.

Less than 2 %.

KRI0028

Windows and

UNIX/Linux servers

without

security patch

coverage.

Percentage of

servers without the

most recent security

patches in

Windows and UNIX/Linux

operating systems,

with respect to the total

of active servers

during the

established period.

Software.

II. External

Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Corrective.

Monthly.

Percentage.

(X/Y)*100.

Number of

servers without the

most recent security

patches

installed.

Total of

servers.

More than 5

%.

Between 2 % and 5 %.

Less than 2

%.

KRI0029

Workstations without

security patch

coverage.

Percentage of

workstations without the

most recent security

patches regardless of

the operating system

in question, with

respect to the total

of workstations of the

institution.

Software.

II. External

Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Corrective.

Monthly.

Percentage.

(X/Y)*100.

Number

of workstations without

the most recent security

patches

installed.

Total number of

workstations.

More than 3

%.

Between 1 % and 3 %.

Less than 1

%.

KRI0030

Database managers (DBM)

without security

patch

coverage.

Percentage of database

managers (DBM) without

coverage of the

most recent security

patches, with

respect to the total of database

managers (DBM)

during the

established period.

Software.

II. External

Fraud.

2.2 Security

of the

Systems.

2.2.1 Breach of

security systems.

Preventive.

Quarterly.

Percentage.

(X/Y)*100.

Number of database

managers

(DBM) without

coverage of

security

patches.

Total number

of database

managers

(DBM).

More than 5

%.

Between 2 % and 5 %.

Less than 2 %.


In the document you are viewing, there may be text, characters or objects that do not display correctly due to conversion to HTML format, so we recommend always taking the digitized image of the DOF or the PDF file of the edition as a reference. The content, form and scope of the published documents are the sole responsibility of their issuer.

INQUIRY

BY DATE

Su

Mo

Tu

We

Th

Fr

Sa

INDICATORS

Exchange Rate and Rates as of 29/08/2026

UDIS

8.809369

See more

SURVEYS

Did you like the new image of the Official Gazette of the Federation website?

No

Yes

Official Gazette of the Federation

Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our menu of services

Electronic address: dof.gob.mx

113

LEGAL NOTICE | SOME RIGHTS RESERVED © 2026

More like this from SHCP

SHCP published 14 documents in the last 30 days. We email you each new one the day it's published.

Topics
Share