2014-11-10
Added · Updated
The Central Bank of Egypt mandates that all registered banks providing or intending to provide online banking services comply with new rules governing information system governance and risk management. Banks holding existing licenses must submit a timeline to align their operations with these rules within three months, with full compliance required within twelve months of plan submission. The regulations establish specific controls for customer identification, authentication methods, transaction security, and outsourcing, while requiring boards of directors to actively manage strategic, operational, compliance, and reputational risks associated with internet banking.
Mr. Chairman of the Board of Directors Bank
Greetings,
In the context of the Central Bank of Egypt's plan to establish a general framework for information system governance and risk management related to the provision of banking services via electronic channels, please be informed that the Board of Directors of the Central Bank of Egypt approved, at its meeting held on November 4, 2014, the Rules Governing the Provision of Online Banking Services in the Egyptian Banking Sector (10 copies attached), which apply to all banks registered with the Central Bank of Egypt that provide or wish to provide online banking services.
It should be noted that all banks that previously obtained a license from the Central Bank of Egypt specifically for online banking services must work to align their status as stated in Item 2-5 of the Rules, taking into account submitting a timeline for alignment regarding the gaps between the Bank's current status and the Rules issued by the Central Bank of Egypt within a period not exceeding three months from the date of this letter to the Supervision and Oversight Sector (Office Supervision Department), with a grace period not exceeding twelve months for the completion of alignment work from the date of submitting the timeline.
In this regard, please be kind enough to send those you deem appropriate from the gentlemen concerned in the fields of Internet Banking Operations, Information Technology and Security, and Risk Management (up to 5 individuals), as two discussion sessions will be held on Tuesday and Thursday, November 25 and 27, 2014, at the 6th floor Conference Hall of the Central Bank of Egypt at 10:00 AM, to answer any inquiries regarding the Rules. The Compliance Officer at your bank must send any inquiries (if any) to the email address ................ by no later than November 16, 2014.
Accept our highest regards,
The Central Bank of Egypt
Rules Governing the Provision of Online Banking Services in the Egyptian Banking Sector
Issue: November 2014
Rules Governing the Provision of Online Banking Services in the Egyptian Banking Sector
Issue: November 2014
| CONTENTS | PAGE |
|---|---|
| 1. Introduction | 1 |
| 1-1 Purpose | 1 |
| 1-2 Scope of the Rules | 2 |
| 1-3 Appendices | 3 |
| 2. Risk Management of Internet Banking Services | 3 |
| 2-1 Risks Associated with Internet Banking Services | 3 |
| 2-2 Board of Directors and Senior Management Responsibilities | 5 |
| 2-3 Information Security Policy | 8 |
| 2-4 Risk Classification of Internet Banking Services | 8 |
| 2-5 Anti-Money Laundering and Counter-Terrorism Financing Rules | 9 |
| 3. Supervisory Controls on Online Banking Services | 10 |
| 3-1 Internet Banking Account Management | 10 |
| 3-2 Identity Verification Means (Authentication) | 12 |
| 3-3 Password Management | 13 |
| 3-4 Controls Specific to Fund Transfer Operations | 13 |
| 3-5 Information Confidentiality and Integrity | 13 |
| 3-6 Application Security | 14 |
| 3-7 Security System Assessment | 15 |
| 3-8 Incident Response and Management | 16 |
| 3-9 Performance Indicators and Business Continuity Assurance | 17 |
| 3-10 Customer Security and Controls for Other Risks | 18 |
| Appendix (A): Best Practices for Establishing Internet Banking Infrastructure | 19 |
| Appendix (B): Examples of Common Cyber Attacks and Vulnerabilities | 21 |
| Appendix (C): Definitions | 22 |
Electronic banking services have become one of the essential elements of banking services, as customer expectations create pressure on banks to provide new banking products. The term electronic banking refers to the integration of traditional banking products and services into a digitized format to achieve customer convenience through electronic and secure communication channels. Electronic banking services include the systems that enable bank customers, whether individuals or legal entities, to access their accounts, conduct their transactions, or obtain information about available products and services through electronic communication channels.
Although the absence or failure of electronic banking services may not affect the stability of the financial system, it negatively affects the trust of users in the services provided through electronic communication channels and threatens the bank's reputation. The Rules Governing the Rules help banks provide these services while maintaining the confidentiality and security of information and enabling customers to rely on them by regulating and securing the infrastructure appropriately.
Given the increasing reliance on technology in banking services in Egypt, further regulatory reforms are required in this field.
Despite the similarity of risks and controls between different communication channels for banking services, these Rules specifically apply to online banking services (also known as Internet Banking) used by customers, whether individuals or legal entities.
The scope of these Rules does not cover other communication channels (such as Automated Teller Machine (ATM) networks, traditional banking services via landline phones, and mobile banking services), and detailed Rules governing these services will be issued separately later.
These Rules and controls represent the minimum threshold required for the provision of online banking services in a secure manner, and each bank must comply with them and ensure that all necessary measures are taken to manage the risks associated with providing this type of banking service.
These Rules include some supervisory controls or objectives related to business continuity, outsourcing, and information system risks. However, detailed Rules governing these areas will be issued separately later.
These Rules do not cover debit card transactions processed through the Four-Party Model.
And payment operations from closed systems conducted via the Internet.
These Rules apply to the provision of online banking services without prejudice to the existing supervisory controls for electronic banking operations issued by the Central Bank of Egypt, as well as the instructions and rules specific to the implementation of banking operations.
These Rules apply to all banks registered with the Central Bank of Egypt, including branches of foreign banks.
The provision of Internet Banking services involves many risks and benefits simultaneously. While these risks are not considered new to banks, the characteristics of Internet Banking services require higher degrees of risk management and create a need for new updates in managing these risks. These risks include, but are not limited to:
These involve the decision to provide Internet Banking services, the type of services provided, and the timing of their provision. This specifically refers to the economic feasibility of providing or continuing these services and whether the return on investment will cover the initial investments and expenses of continuing to provide these services. Poor planning for Internet Banking services and unwise investment decisions can increase the strategic risks faced by banks.
These arise from fraud or errors in transaction execution, system failures, or other unexpected events that may lead to the bank's inability to provide services or expose the bank and its customers to financial losses. While the risk exists in all products and channels provided, the level of transaction risk depends on the structure of banking procedures and transactions, including the types of services provided, the complexity of operations, and the technological aids used.
These risks arise from the rapid increase in the use of Internet Banking services and the differences between electronic and manual operations. Regulatory/Legal challenges include:
The level of reputational risk increases significantly due to the bank's decision to provide Internet Banking services, especially regarding more complex services. The following are some risks that may affect the bank's reputation through the provision of Internet Banking services:
This type of risk arises from the possibility of exploitation by unauthorized parties of weaknesses in the electronic system to cause damage, which results in effects related to the integrity, availability, and confidentiality of data.
The Senior Management must ensure that the Information Security Policy applied at the bank, approved by the Board of Directors and updated periodically, covers Internet Banking services. This helps identify the policies, procedures, and supervisory controls necessary to protect banking operations from breaches and security violations. It also defines the severity of violations and clarifies the evaluation mechanisms and procedures to be taken in case of violation of these policies and procedures.
Senior Management must enhance and spread a security culture at all levels of the bank by emphasizing commitment to high standards of information security. This culture applies to all bank employees.
Banks provide a variety of Internet Banking services to different types of customers, and therefore they do not usually face the same level of inherent risk. For example, customers allowed only to inquire about their account balances online do not face the same level of risk as other customers who transfer funds to external accounts.
This diversity in providing services requires the bank to adopt comprehensive security methods and flexibility at the same time, with a security methodology based on analyzing the risks and threats specific to Internet Banking services, taking into account Inherent Risk and Compensating Controls to reach a level of Residual Risk that falls within the bank's acceptable risk thresholds.
Banks providing Internet Banking services must implement the following:
Banks using any of the electronic service provision channels (e.g., the bank's website, etc.) must apply the Customer Identification Rules for Banks issued by the Anti-Money Laundering and Counter-Terrorism Financing Unit for 2011 to these new customers.
Banks must obtain written consent from the customer wishing to participate in Internet Banking services on a (form) service request or contract (which contains the customer's basic data at minimum (e.g., email, mobile and landline phone numbers, mailing address, etc.), in addition to the terms and conditions that clearly define the rights and obligations between the bank and the customer (please review Item 4-1).
Banks are committed to using reliable methods to verify the identity and authority of customers wishing to subscribe to Internet Banking services, as well as verifying the identity and authority of subscribed customers wishing to execute banking transactions via Internet Banking services.
In corporate banking, in cases where more than one user is authorized to deal with this account.
Banks are committed to obtaining all necessary legal documents to prove the granting of authority to users to conduct transactions on legal entity accounts.
Banks are committed to conducting necessary verification to confirm the identity of the customer when requesting modification of the data of their Internet Banking service account, or modifying any data the customer uses to monitor their banking account activities. This applies to account reactivation and reissuing a new password for an Internet Banking customer, and changing the customer's contact data such as email address, mobile and landline phone numbers, and mailing address. Banks must also consider applying the following standards when dealing with such requests:
Banks are committed to using reliable means to verify the identity of customers using Internet Banking services. Regardless, the authentication process is more effective when combining two of the following elements:
Banks must implement authentication using two means together (e.g., digital signature or one-time passwords issued using security tokens, without allowing the issuance of passwords used once via SMS or email to individual and legal entity customers, etc.) when executing high-risk activities (e.g., transferring funds to external parties, registering new users, changing customer contact data, etc.). The authentication means used must work in conjunction with other applied controls to enhance the following aspects:
Banks must determine the authentication means they will use for Internet Banking services based on the risk level associated with the system, taking into account the evaluation of the type of banking transactions provided via Internet Banking.
Banks need to conduct a detailed assessment to determine if the message used for authentication is secure enough, even if it is...
[RegAlert note: the English text above is a translation of the first 24,000 characters of a 71,979-character original (33% of the document). The remainder was not translated. The complete original-language text is stored with this document.]