2018-04-24
Added
The Proper Conduct of Banking Business Directive no. 363 requires banking corporations to establish principles for cyber-risk management by material service providers and ensure contractual compliance. Banking corporations must periodically map these providers, assess associated risks, and report significant non-compliance to management for decisions on contract continuation or termination. Contracts must include specific provisions such as system hardening, vulnerability testing, employee reliability checks, and data deletion arrangements, while remote access requires strong authentication and security controls. The Directive applies to contracts concluded after its effective date, with existing contracts requiring review within nine months of gazettal.
More like this from BOI
We email you every new BOI publication the day it's published.