2020-04-14 | NRP-23Added · Updated
The Norms Committee of the Central Reserve Bank of El Salvador issued these standards to establish minimum criteria for information security and cybersecurity management. The document mandates compliance for a wide range of supervised entities, including banks, insurance companies, pension funds, and payment system operators. It requires these entities to implement an Information Security Management System, define specific roles for the Board of Directors and Senior Management, and maintain independent specialized security units.
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 1 of 26 CNBCR-07/2020 NRP-23 TECHNICAL STANDARDS FOR INFORMATION SECURITY MANAGEMENT Approval: 14/04/2020 Validity: 01/07/2020
THE NORMS COMMITTEE OF THE CENTRAL RESERVE BANK OF EL SALVADOR,
CONSIDERING: I. That in accordance with Article 2, second paragraph of the Law on Supervision and Regulation of the Financial System, for the proper functioning of the Financial Supervision and Regulation System, it is required that members of the financial system and other supervised entities comply with current regulations and adopt the highest standards of conduct in the development of their business, acts, and operations, in accordance with what is established in the aforementioned Law, in other applicable laws, in regulations, and in the technical norms issued for such purpose. II. That Article 7 of the Law on Supervision and Regulation of the Financial System establishes the entities subject to the supervision of the Superintendence of the Financial System. III. That in accordance with the last paragraph of Article 32 of the Law on Supervision and Regulation of the Financial System, it establishes that, for the purposes of said Law, members of the financial system may use microfilm, optical disks, magnetic media, electronic media, or any other medium that allows archiving documents and information, with the objective of efficiently storing the records, documents, and reports that correspond, including securities. IV. That in accordance with the first paragraph and letter d) of Article 35 of the Law on Supervision and Regulation of the Financial System, directors, managers, and other officials holding positions of direction or administration in the members of the financial system must conduct their business, acts, and operations complying with the highest ethical standards of conduct and acting with the due diligence of a good merchant in their own business, being obligated to comply and ensure that in the institution they direct or work in, the adoption and updating of policies and mechanisms for risk management are fulfilled, and among other actions, they must include the measures that will be adopted to prevent possible non-compliance with regulatory requirements and those that will be adopted in the event that they have incurred in them. V. That in accordance with letters a) and g) of Article 99 of the Law on Supervision and Regulation of the Financial System, the Central Reserve Bank of El Salvador is the institution responsible for the approval of technical norms related to risk management by supervised entities, as well as those in which the minimum conditions that the premises, their security measures, and the conservation and archiving of documentation of the members of the financial system must meet are defined.
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 2 of 26 CNBCR-07/2020 NRP-23 TECHNICAL STANDARDS FOR INFORMATION SECURITY MANAGEMENT Approval: 14/04/2020 Validity: 01/07/2020 VI. That taking international standards as a reference, which suggest, among other good practice activities, the implementation of an Information Security Governance, so that through it entities ensure they adequately manage the security of the information they handle from their clients and of the entity itself. VII. That it is of utmost importance that entities guarantee that the information they collect, process, and store from their clients is subject to due confidentiality; is always available for consultation and use by clients and entities; and is intact according to the truthfulness of the legal documents from which it was extracted. VIII. That the speed with which the information systems environment evolves makes it necessary to issue provisions containing the necessary specifications so that entities have the appropriate technology to perform their functions efficiently.
THEREFORE, in virtue of the regulatory powers conferred by Article 99 of the Law on Supervision and Regulation of the Financial System,
AGREES to issue the following:
TECHNICAL STANDARDS FOR INFORMATION SECURITY MANAGEMENT
CHAPTER I OBJECT, SUBJECTS, AND TERMS
Object Art. 1.- These Norms have as their objective to establish the minimum criteria for the management of information security and its cybersecurity, in accordance with international best practices, the nature, size, risk profile of the entities, and volume of their operations.
Subjects Art. 2.- The subjects obliged to comply with the provisions established in these Norms are the following: a) Banks constituted in El Salvador, their offices abroad, and their subsidiaries; branches and offices of foreign banks established in the country; b) Companies that, in accordance with the law, integrate financial conglomerates, or that the Superintendence declares as such, which includes both their controlling companies and their member companies;
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 3 of 26 CNBCR-07/2020 NRP-23 TECHNICAL STANDARDS FOR INFORMATION SECURITY MANAGEMENT Approval: 14/04/2020 Validity: 01/07/2020 c) Pension fund management institutions and the funds they manage; d) Insurance companies, their branches abroad, and the branches of foreign insurance companies established in the country, and the Insurance Cooperative Associations constituted in the country, insofar as it does not contradict their respective Law; e) Stock exchanges, brokerage houses, companies specialized in the deposit and custody of securities, risk classifiers, and agents specialized in the valuation of securities; f) Cooperative banks, savings and credit companies, and federations regulated by the Law on Cooperative Banks and Savings and Credit Companies; g) Reciprocal guarantee companies and their local reinsurance companies; h) Companies that offer complementary services to the financial services of the members of the financial system, particularly those in which they participate as investors; i) Administrators or operators of payment systems and securities settlement societies; j) The Social Fund for Housing and the National Fund for Popular Housing, insofar as it does not contradict their creation laws nor what is provided by the Court of Accounts; k) The Social Prevision Institute of the Armed Forces; l) The Salvadoran Institute of Pensions. (1) m) The Agricultural Development Bank, the Mortgage Bank of El Salvador, S.A., and the Development Bank of El Salvador, insofar as it does not contradict their creation laws nor what is provided by the Court of Accounts; n) Securitization companies and the funds they manage; o) Product and services exchanges; p) Investment fund managers and the funds they manage; q) Electronic Money Provider Companies; r) Data Information Agencies; s) The Pension Unit of the Salvadoran Social Security Institute. (2) t) The Salvadoran Social Security Institute, the latter with respect to the Public Pension System, the Professional Risks Regime, and technical health reserves; and (2) u) Investment banks, their offices abroad, and their subsidiaries. (2)
Terms Art. 3.- For the purposes of these Norms, the terms indicated below have the following meaning: a) Information asset: component that supports one or more business processes and generates value to the entity. Information assets can be of various types, among them: data or information, services (processes), computer programs, physical devices, communication networks, information supports, auxiliary equipment, and physical installations, and intangibles (brands);
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 4 of 26 CNBCR-07/2020 NRP-23 TECHNICAL STANDARDS FOR INFORMATION SECURITY MANAGEMENT Approval: 14/04/2020 Validity: 01/07/2020 b) Senior Management: the Executive President, Executive Director, General Manager, or whoever acts in their place, and the executive positions that report to them, for the case of the Development Bank of El Salvador, the President; c) Application, program, or computer system: any software used by the entity for the collection, storage, processing, visualization, or transmission of information related to the financial products or services that the entity offers to its clients; d) Central Bank: Central Reserve Bank of El Salvador; e) Significant change: Corresponds to a change in the business model, mergers, or acquisitions; (1) f) Alternate data center: refers to an installation, separate from the entity's physical infrastructure, with a technological infrastructure that guarantees that critical business operations can continue when the main data center is not available; (1) g) Main data center: set of computer equipment on which operating systems and applications that process and store information of the financial products and services that entities offer to their clients operate; (1) h) Cyber threat or cyber threat: potential occurrence of a situation that could become a cyberattack; (1) i) Cyberattack or cyber attack: organized or premeditated action by one or more agents that use the services or applications of cyberspace or are the target of the same or where cyberspace is the source or tool for the realization of unauthorized access to the entity's information, compromising the security of the entity's information; (1) j) Cyberspace: complex environment resulting from the interaction of people, software, and services on the Internet through technological devices connected to said network, which does not exist in any physical form; (1) k) Cyber risk, cyber risk, or cybersecurity risk: possible negative results derived from failures in the security of the technological infrastructure or associated with cyberattacks; (1) l) Cybersecurity: development of technical capabilities to defend and anticipate cyber threats in order to protect and ensure the confidentiality, integrity, and availability of information in cyberspace and which is essential for the operation of the entity; (1) m) Confidentiality: property of information by which it is considered accessible only to those duly authorized and only for the specific and expressly delimited purposes; (1) n) Secure Configuration: process aimed at eliminating an attack vector by patching vulnerabilities and deactivating non-essential services; (1) o) Availability: property of information by which it remains organized and accessible for use when required by authorized users; (1) p) Entity: subject obliged to comply with the provisions of these Norms, listed in Article 2 of the same; (1)
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 5 of 26 CNBCR-07/2020 NRP-23 TECHNICAL STANDARDS FOR INFORMATION SECURITY MANAGEMENT Approval: 14/04/2020 Validity: 01/07/2020 q) Event: occurrence or series of occurrences that can be internal or external to the entity, originated by the same cause, that occur during the same period; (1) r) Cybersecurity event: occurrence of a situation that could affect the protection or assurance of the entity's information, infrastructure, or technological platform and applications that are essential to the business; (1) s) Authentication factor: information used to verify the identity of a service or a person; (1) t) Information Security Management: processes by which information security is prevented, detected, and responded to, regardless of its format, including paper documents, digital and intellectual property, and verbal or visual communications; (1) u) Information Security Governance: set of responsibilities and practices that aim to provide strategic direction and ensure that corporate objectives related to information security are achieved, managing it in accordance with international standards, according to the nature, size, risk profile of the entities, and volume of their operations, and verifying that the company's resources are employed responsibly for these purposes; (1) v) Information security or cybersecurity incident: one or more specific events, associated with a cyberattack, a possible failure in the information security policy, in the controls, or a previously unknown situation relevant to information security, which has a significant probability of compromising business operations and damaging said security; (1) w) Information: set of organized and understandable data that communicate a message. Information can be printed or digital. In case the information is digital, it can be in formats of any type, such as electronic, optical, or magnetic. Any communication (oral, visual, or written) that could include facts, data, or opinions in any medium or form will also be considered; (1) x) Infrastructure or technological platform: hardware and software components on which information related to financial products and services offered by the entity is collected, processed, transmitted, and stored; (1) y) Integrity: property by which it is safeguarded that information is complete, accurate, and valid; (1) z) ISAE (Information Security for Event Management) or SIEM by its English acronym: information system that provides real-time analysis of security alerts generated by applications, security devices, and network elements, such as for example system event log centralization systems; (1) aa) Board of Directors: collegiate body in charge of the administration of the entity, with supervision, direction, and control functions or equivalent body. For the case of Cooperative Associations, it will be the Board of Directors, or as defined in its Creation Law; (1) bb) Backup: copy of the original information made with the intention of having a means for its recovery in case of partial or total loss of these; (1) cc) Information Security Program: set of plans implemented to
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 6 of 26 CNBCR-07/2020 NRP-23 TECHNICAL STANDARDS FOR INFORMATION SECURITY MANAGEMENT Approval: 14/04/2020 Validity: 01/07/2020 preserve and continuously improve information security, based on business requirements and risk analysis; (1) dd) Provider: Providers that provide technology, information system, infrastructure, or cybersecurity services to entities, to whom access is granted for a determined period of time; (1) ee) Resilience: is the capacity of a mechanism or system to recover its initial state when the perturbation to which it may have been subjected has ceased; (1) ff) Information Security: set of measures that allow safeguarding and protecting information complying with the properties of confidentiality, integrity, and availability of the same, in order that threats do not materialize; (1) gg) Physical security: application of physical barriers and control procedures, as preventive measures and countermeasures against threats to the entity's information assets and information; (1) hh) Logical security: application of barriers and procedures that safeguard access to information and only allow access to them to authorized persons or services, leaving evidence thereof; (1) ii) Critical services: are the services and activities defined as priorities whose unavailability compromises the existence of the entity; (1) jj) Information Security Management System (SIMS): refers to the design, implementation, and continuous maintenance of a set of policies and processes to effectively manage information security and cybersecurity; (1) kk) Superintendence: Superintendence of the Financial System; (1) ll) Outsourcing of information technology activities, operations, or processes: occurs when the entity entrusts the performance of information technology activities, operations, or processes, related to the entity's financial services or products, to a third party, that is, to a natural or legal person distinct from the entity; (1) mm) Cybersecurity Unit (UCIB): unit in charge of monitoring, evaluating, and defending the entity's information systems such as websites, applications, databases, main or alternate data centers, servers, networks, desktops, devices, among others; and (1) nn) Vulnerability: weakness of an asset or control that can be exploited or used by a threat. All those threats that arise from the interaction of systems in cyberspace are taken into account. (1)
CHAPTER II ROLES AND RESPONSIBILITIES
Information Security and Cybersecurity Function Art. 4.- Entities must have an organizational structure in accordance with their products, services, operations, size, risk profile, and business model, in such a way that it clearly delimits the functions, roles, responsibilities, and powers associated with information security and cybersecurity, as well as the levels of dependence and interrelation that correspond with each of the other areas of the entity. Likewise, entities must ensure that all their personnel recognize information security and cybersecurity as one of their responsibilities, applying the confidentiality measures that may be necessary. The information whose security must be preserved will be that which, according to the classification of information assets made by the entity, requires a security or protection treatment.
Board of Directors Responsibilities Art. 5.- The Board of Directors or equivalent body will be responsible for establishing adequate governance and management of information security, so it must perform at least the following: a) Approve the necessary resources for the establishment, implementation, monitoring, and maintenance of information security management, in order to have the appropriate infrastructure, methodology, tactics, and personnel. Likewise, it must appoint a person responsible for managing information security, who will have permanent and direct communication with Senior Management, who in turn will report directly to the Board of Directors. The Board of Directors will record its appointment in the Minutes Point, which must be sent to the Superintendence no later than ten business days after said appointment; b) Approve the information security program and the SIMS structure; and c) Require Internal Audit to verify the existence and compliance of the SIMS structure.
Senior Management Responsibilities Art. 6.- To implement information security management in accordance with the provisions of the Board of Directors, the Senior Management of the entities must perform at least the following: a) Support the information security program; b) Promote the continuous improvement of the SIMS and ensure its permanent validity; and c) Support the information security manager in the execution of information security strategies and tactics required, in the event of an unforeseen information security or cybersecurity incident. Senior Management must communicate this directly to the Board of Directors.
Risk Committee Responsibilities Art. 7.- Entities must have a Risk Committee which will observe what is established in these Norms and in the (NRP-17) approved by the Central Bank, through its Norms Committee. In matters of information security risk management, the Risk Committee,
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 7 of 26 CNBCR-07/2020 NRP-23 TECHNICAL STANDARDS FOR INFORMATION SECURITY MANAGEMENT Approval: 14/04/2020 Validity: 01/07/2020 or whoever acts in their place, will be responsible for carrying out at least the following: a) Propose to the Board of Directors the SIMS structure; b) Review, evaluate, and propose for approval by the Board of Directors the information security program and resources, said resources must be separate from the budgets destined to any other area of the entity; and c) Monitor the management of information security.
Risk Unit Responsibility Art. 8.- Regarding information security management, the Risk Unit, or whoever acts in their place, must perform the following: a) Propose to the Risk Committee or whoever acts in their place, the creation of specialized Committees, areas, or positions for the fulfillment of responsibilities related to information security management; and b) Ensure that information security management is consistent with the policies and methodologies applied for risk management. Due to its hierarchical position and functions, the designated person or the organizational unit must ensure that its reports are made known to the Board of Directors or to the instance that it delegates.
Specialized Information Security Unit or Area Art. 9.- Based on its size, nature, and complexity of products, services, and operations, the information security function will be performed by a specialized unit or area of the entity. The specialized unit or area must be independent with respect to business or support areas. The Board of Directors, or equivalent body of the entity, must define the specialized unit or area in information security that will be responsible for designing, implementing, and maintaining a SIMS. Said unit must perform at least the following: a) Draft and propose to the Risk Committee or whoever acts in their place,
Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 8 of 26 CNBCR-07/2020 NRP-23 TECHNICAL STANDARDS FOR INFORMATION SECURITY MANAGEMENT Approval: 14/04/2020 Validity: 01/07/2020