2014-11-10

Added · Updated

Rules governing the provision of online banking services

The Central Bank of Egypt mandates that all registered banks providing or intending to provide online banking services comply with new rules governing information system governance and risk management. Banks holding existing licenses must submit a timeline to align their operations with these rules within three months, with full compliance required within twelve months of plan submission. The regulations establish specific controls for customer identification, authentication methods, transaction security, and outsourcing, while requiring boards of directors to actively manage strategic, operational, compliance, and reputational risks associated with internet banking.

Central Bank of Egypt logo

Egypt

Central Bank of Egypt

Click to view thumbnail

Mr. Chairman of the Board of Directors Bank

Greetings,

In the context of the Central Bank of Egypt's plan to establish a general framework for information system governance and risk management related to the provision of banking services via electronic channels, please be informed that the Board of Directors of the Central Bank of Egypt approved, at its meeting held on November 4, 2014, the Rules Governing the Provision of Online Banking Services in the Egyptian Banking Sector (10 copies attached), which apply to all banks registered with the Central Bank of Egypt that provide or wish to provide online banking services.

It should be noted that all banks that previously obtained a license from the Central Bank of Egypt specifically for online banking services must work to align their status as stated in Item 2-5 of the Rules, taking into account submitting a timeline for alignment regarding the gaps between the Bank's current status and the Rules issued by the Central Bank of Egypt within a period not exceeding three months from the date of this letter to the Supervision and Oversight Sector (Office Supervision Department), with a grace period not exceeding twelve months for the completion of alignment work from the date of submitting the timeline.

In this regard, please be kind enough to send those you deem appropriate from the gentlemen concerned in the fields of Internet Banking Operations, Information Technology and Security, and Risk Management (up to 5 individuals), as two discussion sessions will be held on Tuesday and Thursday, November 25 and 27, 2014, at the 6th floor Conference Hall of the Central Bank of Egypt at 10:00 AM, to answer any inquiries regarding the Rules. The Compliance Officer at your bank must send any inquiries (if any) to the email address ................ by no later than November 16, 2014.

Accept our highest regards,

The Central Bank of Egypt

Rules Governing the Provision of Online Banking Services in the Egyptian Banking Sector

Issue: November 2014

The Central Bank of Egypt

Rules Governing the Provision of Online Banking Services in the Egyptian Banking Sector

Issue: November 2014

Contents

CONTENTSPAGE
1. Introduction1
1-1 Purpose1
1-2 Scope of the Rules2
1-3 Appendices3
2. Risk Management of Internet Banking Services3
2-1 Risks Associated with Internet Banking Services3
2-2 Board of Directors and Senior Management Responsibilities5
2-3 Information Security Policy8
2-4 Risk Classification of Internet Banking Services8
2-5 Anti-Money Laundering and Counter-Terrorism Financing Rules9
3. Supervisory Controls on Online Banking Services10
3-1 Internet Banking Account Management10
3-2 Identity Verification Means (Authentication)12
3-3 Password Management13
3-4 Controls Specific to Fund Transfer Operations13
3-5 Information Confidentiality and Integrity13
3-6 Application Security14
3-7 Security System Assessment15
3-8 Incident Response and Management16
3-9 Performance Indicators and Business Continuity Assurance17
3-10 Customer Security and Controls for Other Risks18
Appendix (A): Best Practices for Establishing Internet Banking Infrastructure19
Appendix (B): Examples of Common Cyber Attacks and Vulnerabilities21
Appendix (C): Definitions22

1 - Introduction

1-1 Purpose

Electronic banking services have become one of the essential elements of banking services, as customer expectations create pressure on banks to provide new banking products. The term electronic banking refers to the integration of traditional banking products and services into a digitized format to achieve customer convenience through electronic and secure communication channels. Electronic banking services include the systems that enable bank customers, whether individuals or legal entities, to access their accounts, conduct their transactions, or obtain information about available products and services through electronic communication channels.

Although the absence or failure of electronic banking services may not affect the stability of the financial system, it negatively affects the trust of users in the services provided through electronic communication channels and threatens the bank's reputation. The Rules Governing the Rules help banks provide these services while maintaining the confidentiality and security of information and enabling customers to rely on them by regulating and securing the infrastructure appropriately.

Given the increasing reliance on technology in banking services in Egypt, further regulatory reforms are required in this field.

1-2 Scope of the Rules

Despite the similarity of risks and controls between different communication channels for banking services, these Rules specifically apply to online banking services (also known as Internet Banking) used by customers, whether individuals or legal entities.

The scope of these Rules does not cover other communication channels (such as Automated Teller Machine (ATM) networks, traditional banking services via landline phones, and mobile banking services), and detailed Rules governing these services will be issued separately later.

These Rules and controls represent the minimum threshold required for the provision of online banking services in a secure manner, and each bank must comply with them and ensure that all necessary measures are taken to manage the risks associated with providing this type of banking service.

These Rules include some supervisory controls or objectives related to business continuity, outsourcing, and information system risks. However, detailed Rules governing these areas will be issued separately later.

These Rules do not cover debit card transactions processed through the Four-Party Model.

And payment operations from closed systems conducted via the Internet.

These Rules apply to the provision of online banking services without prejudice to the existing supervisory controls for electronic banking operations issued by the Central Bank of Egypt, as well as the instructions and rules specific to the implementation of banking operations.

These Rules apply to all banks registered with the Central Bank of Egypt, including branches of foreign banks.

1-3 Appendices

  • Appendix (A): Best Practices for Establishing Internet Banking Infrastructure
  • Appendix (B): Examples of Common Cyber Attacks
  • Appendix (C): Definitions

2 - Risk Management of Internet Banking Services

2-1 Risks Associated with Internet Banking Services

The provision of Internet Banking services involves many risks and benefits simultaneously. While these risks are not considered new to banks, the characteristics of Internet Banking services require higher degrees of risk management and create a need for new updates in managing these risks. These risks include, but are not limited to:

Strategic Risks:

These involve the decision to provide Internet Banking services, the type of services provided, and the timing of their provision. This specifically refers to the economic feasibility of providing or continuing these services and whether the return on investment will cover the initial investments and expenses of continuing to provide these services. Poor planning for Internet Banking services and unwise investment decisions can increase the strategic risks faced by banks.

Operational/Transaction Risks:

These arise from fraud or errors in transaction execution, system failures, or other unexpected events that may lead to the bank's inability to provide services or expose the bank and its customers to financial losses. While the risk exists in all products and channels provided, the level of transaction risk depends on the structure of banking procedures and transactions, including the types of services provided, the complexity of operations, and the technological aids used.

Compliance/Legal Risks:

These risks arise from the rapid increase in the use of Internet Banking services and the differences between electronic and manual operations. Regulatory/Legal challenges include:

  • Electronic legal agreements with customers to use the Internet Banking service.
  • The methods banks use to verify customer identity, which constitute a source of legal risk that requires adequate controls to mitigate.
  • In light of the bank's commitment to the Central Bank, Banking, and Currency Law No. 88 of 2002, banks must put in place procedures and controls to maintain data privacy and account confidentiality to manage the increasing risks associated with providing Internet Banking services, as well as legal liability to customers in the event of privacy breaches, or any other problems due to hacking, fraud, or other technological failures, and to protect customer data from theft.
  • Banks providing Internet Banking services face a higher degree of compliance risk due to the changing nature of technology and regulatory amendments aimed at dealing with problems specific to providing this type of service.
  • Maintaining required compliance documents related to records, applications, and reports, advice, and regulations.
  • Identifying and evaluating money laundering and terrorism financing risks that may arise from banking services provided via the Internet, as this evaluation must be completed before launching Internet Banking services.

Reputational Risks:

The level of reputational risk increases significantly due to the bank's decision to provide Internet Banking services, especially regarding more complex services. The following are some risks that may affect the bank's reputation through the provision of Internet Banking services:

  • Loss of trust due to unauthorized transactions on the customer's account.
  • Disclosure of confidential customer information to unauthorized parties or theft thereof.
  • Failure to provide reliable services due to repeated service outages or long downtime.
  • Customer complaints about the difficulty of using Internet Banking services or the inability of bank support staff to resolve these issues.

Cyber Risks:

This type of risk arises from the possibility of exploitation by unauthorized parties of weaknesses in the electronic system to cause damage, which results in effects related to the integrity, availability, and confidentiality of data.

2-2 Board of Directors and Senior Management Responsibilities

2-2-1 The Board of Directors and Senior Management are responsible for participating in the preparation of the bank's business strategy and making a clear strategic decision regarding the bank's plan to provide Internet Banking services. Specifically, the Board of Directors must ensure the following:

  • Internet Banking plans align with the bank's strategic objectives.
  • Analysis of risks associated with proposed Internet Banking services.
  • Preparation of appropriate procedures to monitor and mitigate risks, including those identified.
  • Continuous review of the evaluation of Internet Banking service results according to specified plans and objectives.

2-2-2 The Board of Directors and Senior Management must ensure the identification and mitigation of risks associated with Internet Banking services mentioned in Item 2-1 in appropriate ways, as follows:

  • Establish effective supervision of risks associated with providing Internet Banking services, including defining responsibilities, authorities, and supervisory controls for managing these risks.
  • The Board of Directors and Senior Management must have a thorough understanding of Internet Banking operations, which may present challenges different from traditional risk management as described in Item 2-1.
  • The Board of Directors and Senior Management must ensure that the bank does not provide new Internet Banking services or adopt new technological means unless the bank has the necessary expertise to manage risks efficiently. Staff and management expertise must match the technical nature and degree of complexity of applications and technologies specific to Internet Banking services.
  • The Board of Directors and Senior Management must determine the bank's risk appetite regarding Internet Banking services and ensure that risk management processes related to these services are included in the bank's general risk management methodology. Existing policies and processes related to risk management must be reviewed to ensure their adequacy to mitigate new risks that may result from Internet Banking services.
  • Internal Audit Management must provide the Board of Directors, the Audit Committee, and Senior Management with an independent and objective assessment of the effectiveness of supervisory controls implemented to mitigate risks arising from providing Internet Banking services, including technology risks.

2-2-3 Review and Approval of Key Aspects of the Bank's Security Supervision Process:

  • The Board of Directors and Senior Management must oversee the continuous development and maintenance of the security control infrastructure that protects the confidentiality of systems and data for Internet Banking services from any internal or external threats. To ensure the effectiveness of securing Internet Banking services, the Board of Directors and Senior Management must ensure the following actions are taken:
    • Define clear responsibilities for overseeing the establishment and management of the bank's security policies.
    • Provide necessary protection to prevent unauthorized persons from accessing the computer environment, which includes all vital systems, network servers, databases, applications, communications, and security systems specific to Internet Banking services.
    • Provide necessary electronic controls to prevent any unauthorized internal or external parties from accessing applications and databases specific to Internet Banking services.
    • Periodic review of security procedure and system testing operations (e.g., conducting periodic penetration testing as shown in Item 3-8), including continuous monitoring of developments in security systems in this field, and downloading and preparing appropriate software patches and service packs and necessary measures, following the required tests.

2-2-4 Establish a comprehensive and continuous mechanism for conducting Due Diligence and supervising outsourcing operations and the bank's relationships with other external parties relied upon to provide Internet Banking services. The Board of Directors and Senior Management should focus on the following points, including but not limited to:

  • Full awareness of the risks resulting from any arrangements regarding outsourcing or partnerships related to Internet Banking services, in addition to providing necessary resources to investigate these arrangements.
  • Conducting necessary due diligence regarding the competence, system infrastructure, and financial capacity of the partner or external service provider before making any outsourcing or partnership agreements.
  • Clearly defining contractual responsibilities for all parties regarding outsourcing or partnership agreements. For example, the responsibilities for providing information to the service provider and receiving it from them must be clearly defined.
  • Ensure that outsourcing service contracts include clauses prohibiting the disclosure of confidential information to third parties and service level agreements, which include, but are not limited to, defining roles, responsibilities, time required to execute the service, escalation procedures and data, and penalties in case of non-compliance, in addition to clauses preserving the bank's right to audit service providers or rely on audits conducted by approved audit firms (independent audit reports).
  • All systems and processes for Internet Banking services conducted through outsourcing must be subject to the bank's risk assessment system and information security and privacy policies that comply with the bank's standards.
  • Conduct internal and/or external audits periodically on operations conducted through outsourcing, and the scope of audit work should not be less than that applied at the internal level in the bank.
  • Provide all evaluation reports to the inspectors of the Supervision and Oversight Sector of the Central Bank of Egypt.
  • Prepare appropriate contingency plans for Internet Banking services conducted through outsourcing.
  • Procedures for contract termination must be provided, and these procedures must ensure the preservation of business continuity and data integrity, as well as its transfer and disposal.
  • If Internet Banking services are outsourced to parties outside the Arab Republic of Egypt, banks must take necessary measures to comply with Egyptian laws and legislation and the jurisdiction of Egyptian courts in the event of any disputes.
  • In accordance with Item 1-20, detailed Rules governing outsourcing activities will be issued separately, including detailed supervisory controls, supervisory objectives, and a list of systems and services permitted to be outsourced. Until these Rules are issued, banks must not make any arrangements regarding the outsourcing of Internet Banking services or their applications without prior approval from the Central Bank of Egypt.

2-3 Information Security Policy

The Senior Management must ensure that the Information Security Policy applied at the bank, approved by the Board of Directors and updated periodically, covers Internet Banking services. This helps identify the policies, procedures, and supervisory controls necessary to protect banking operations from breaches and security violations. It also defines the severity of violations and clarifies the evaluation mechanisms and procedures to be taken in case of violation of these policies and procedures.

Senior Management must enhance and spread a security culture at all levels of the bank by emphasizing commitment to high standards of information security. This culture applies to all bank employees.

2-4 Risk Classification of Internet Banking Services

Banks provide a variety of Internet Banking services to different types of customers, and therefore they do not usually face the same level of inherent risk. For example, customers allowed only to inquire about their account balances online do not face the same level of risk as other customers who transfer funds to external accounts.

This diversity in providing services requires the bank to adopt comprehensive security methods and flexibility at the same time, with a security methodology based on analyzing the risks and threats specific to Internet Banking services, taking into account Inherent Risk and Compensating Controls to reach a level of Residual Risk that falls within the bank's acceptable risk thresholds.

2-5 Anti-Money Laundering and Counter-Terrorism Financing Rules

Banks providing Internet Banking services must implement the following:

  • Compliance with the Anti-Money Laundering Law issued by Law No. 80 of 2006 and its executive regulations, and the supervisory controls for banks regarding anti-money laundering and counter-terrorism financing issued by the Central Bank of Egypt in 2008, and the Customer Identification Rules for Banks issued by the Anti-Money Laundering and Counter-Terrorism Financing Unit in 2011.
  • Applying enhanced due diligence procedures for high-risk customers and transactions as stated in Item Eight (Enhanced Due Diligence Procedures for High-Risk Customers or Services and Banking Operations) of the Customer Identification Rules for Banks issued by the Anti-Money Laundering and Counter-Terrorism Financing Unit in 2011.
  • Giving sufficient attention to the indicative indicators in Item Seven (Indicative Indicators for Identifying Transactions Suspected of Involving Money Laundering or Terrorism Financing) of the supervisory controls for banks regarding anti-money laundering and counter-terrorism financing issued by the Central Bank of Egypt in 2008.
  • In the event of suspicion of any transactions conducted via the Internet, reporting them to the Anti-Money Laundering and Counter-Terrorism Financing Authority, in accordance with the provisions of the Anti-Money Laundering Law issued by Law No. 80 of 2006.

3 - Supervisory Controls on Online Banking Services

3-1 Internet Banking Account Management

Banks using any of the electronic service provision channels (e.g., the bank's website, etc.) must apply the Customer Identification Rules for Banks issued by the Anti-Money Laundering and Counter-Terrorism Financing Unit for 2011 to these new customers.

Banks must obtain written consent from the customer wishing to participate in Internet Banking services on a (form) service request or contract (which contains the customer's basic data at minimum (e.g., email, mobile and landline phone numbers, mailing address, etc.), in addition to the terms and conditions that clearly define the rights and obligations between the bank and the customer (please review Item 4-1).

Banks are committed to using reliable methods to verify the identity and authority of customers wishing to subscribe to Internet Banking services, as well as verifying the identity and authority of subscribed customers wishing to execute banking transactions via Internet Banking services.

In corporate banking, in cases where more than one user is authorized to deal with this account.

Banks are committed to obtaining all necessary legal documents to prove the granting of authority to users to conduct transactions on legal entity accounts.

Banks are committed to conducting necessary verification to confirm the identity of the customer when requesting modification of the data of their Internet Banking service account, or modifying any data the customer uses to monitor their banking account activities. This applies to account reactivation and reissuing a new password for an Internet Banking customer, and changing the customer's contact data such as email address, mobile and landline phone numbers, and mailing address. Banks must also consider applying the following standards when dealing with such requests:

  • In the event the customer submits a request to modify their data in person, the necessary procedures must be applied to verify their identity.
  • In the case of modification requests submitted via Internet Banking services, the authentication method described in Item 3-3 must be used, ensuring the existence of effective monitoring mechanisms.
  • Banks must apply necessary procedures to verify the customer's identity in the event they surrender information or tools or devices that allow them to access the Internet Banking account (e.g., PIN, security tokens, etc.).
  • In the absence of similar standards to those described above, banks must avoid sending important documents (e.g., checkbooks and alternative security tokens, etc.) to customers who have recently changed their mailing addresses, in particular. The customer is obligated to receive these documents in person from a bank branch after verifying their identity according to prevailing rules.
  • Conduct additional verification and inspection to confirm the customer's identity, with regard to requests made via telephone (calls received from customers only) to send new security tokens or any other important credentials, such as additional verification: asking the customer for information that changes from time to time, in addition to questions related to personal transactions in general (e.g., approximate account balances and the last transactions executed on the account).

3-2 Identity Verification Means (Authentication)

Banks are committed to using reliable means to verify the identity of customers using Internet Banking services. Regardless, the authentication process is more effective when combining two of the following elements:

  • Something known to the customer (e.g., username and password).
  • Something possessed by the customer (e.g., digital signature or one-time passwords issued using security tokens).
  • Something unique and specific to the customer (e.g., biometric traits, such as fingerprints).

Banks must implement authentication using two means together (e.g., digital signature or one-time passwords issued using security tokens, without allowing the issuance of passwords used once via SMS or email to individual and legal entity customers, etc.) when executing high-risk activities (e.g., transferring funds to external parties, registering new users, changing customer contact data, etc.). The authentication means used must work in conjunction with other applied controls to enhance the following aspects:

  • Non-repudiation
  • Data integrity and security
  • Data confidentiality
  • Identity validity

Banks must determine the authentication means they will use for Internet Banking services based on the risk level associated with the system, taking into account the evaluation of the type of banking transactions provided via Internet Banking.

Banks need to conduct a detailed assessment to determine if the message used for authentication is secure enough, even if it is...


[RegAlert note: the English text above is a translation of the first 24,000 characters of a 71,979-character original (33% of the document). The remainder was not translated. The complete original-language text is stored with this document.]

More like this from CBE

CBE published 2 documents in the last 30 days. We email you each new one the day it's published.

Share