2022-02-21 | NRP-32

Added · Updated

Technical Standards on Cybersecurity Measures in Digital Channels

The Committee of Standards of the Central Reserve Bank of El Salvador issued CNBCR-02/2022, effective March 8, 2022, imposing cybersecurity obligations on banks, cooperative banks, savings and credit societies, and investment banks. The regulation mandates the implementation of multi-factor authentication, requiring at least three distinct factors for client identity verification in digital channels, including specific password length requirements. Entities must also deploy network monitoring, vulnerability management, encryption, and incident response plans to secure information systems and digital transactions.

Superintendencia del Sistema Financiero logo

El Salvador

Superintendencia del Sistema Financiero

Click to view thumbnail

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 1 of 17 CNBCR-02/2022 NRP-32 TECHNICAL STANDARDS ON CYBERSECURITY MEASURES IN DIGITAL CHANNELS Approval: 21/02/2022 Validity: 8/03/2022

THE COMMITTEE OF STANDARDS OF THE CENTRAL RESERVE BANK OF EL SALVADOR,

CONSIDERING: I. That Article 2, second paragraph of the Law on Supervision and Regulation of the Financial System, establishes that for the proper functioning of the Financial Supervision and Regulation System, it is required that the members of the financial system and other supervised entities comply with current regulations and the adoption of the highest standards of conduct in the development of their business, acts, and operations, in accordance with what is established in the aforementioned Law, in other applicable laws, in regulations, and in technical standards issued for such effect. II. That Article 7 of the Law on Supervision and Regulation of the Financial System establishes the entities subject to the supervision of the Superintendence of the Financial System. III. That Article 35, letters d) and g) of the Law on Supervision and Regulation of the Financial System, establishes that directors, managers, and other officials holding positions of direction or administration in the members of the financial system are obligated to comply and ensure that entities adopt and update policies and mechanisms for risk management, including among other actions, identifying, evaluating, mitigating, and disclosing them in accordance with international best practices. In said policies, measures to be adopted to prevent possible non-compliance with regulatory requirements and those to be adopted in the event of having incurred in them must be included, defining in both situations the parameters that will guide the action and those responsible for implementing them. Likewise, they must ensure that entities comply with the efficient functioning of systems for recording, processing, storing, transmitting, producing, securing, and controlling information flows. IV. That Article 56, letter l) of the Banking Law, establishes that banks may carry out operations and provide services to the public through the use of automated equipment and systems, establishing in the respective contracts the bases for determining the operations and services whose provision is agreed upon; the means of user identification and the responsibilities corresponding to their use; and the means by which the creation, transmission, modification, or extinction of rights and obligations inherent to the operations and services in question are recorded. When these operations are carried out through contracts of adhesion, the models of said contracts must be previously deposited with the Superintendence, which may, through a reasoned decision, within a period not exceeding thirty days from the date of deposit of the model, require the necessary changes

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 2 of 17 CNBCR-02/2022 NRP-32 TECHNICAL STANDARDS ON CYBERSECURITY MEASURES IN DIGITAL CHANNELS Approval: 21/02/2022 Validity: 8/03/2022 when they contain clauses that oppose legislation or when they are considered violative of client rights. In all cases, the Bank will be obligated to explain to the client the implications of the contract prior to its subscription. V. That Article 63 of the Banking Law and Article 41 of the Law on Cooperative Banks and Savings and Credit Societies establish that banks and cooperative banks, respectively, must elaborate and implement policies and control systems that allow them to adequately manage their financial and operational risks. VI. That Article 155 of the Law on Cooperative Banks and Savings and Credit Societies establishes that Savings and Credit Societies will be subject to the provisions of the Banking Law, in the terms indicated therein, with the provisions of Article 63 of the Banking Law being applicable. VII. That Article 99 of the Law on Supervision and Regulation of the Financial System establishes that, by virtue of said Law, the Central Reserve Bank is the institution responsible for the approval of the technical regulatory framework that must be issued in accordance with this Law and other laws regulating the supervised entities. In the fulfillment of this responsibility, the Central Reserve Bank must ensure that the applicable regulatory framework for the financial system is periodically reviewed, seeking its timely update. VIII. That to bring financial services closer to people, it becomes necessary for banking to penetrate through digital channels, which allows for a sustained adoption of new payment schemes, which constitute a dynamic and novel means for people conducting operations in the financial system, becoming a complement to the channels that use traditional instruments. IX. That it is necessary to have technical standards that establish the conditions and requirements that financial institutions must observe to carry out operations and provide their services through digital channels, in concordance with international best practices and the specific characteristics of the Salvadoran market.

THEREFORE, by virtue of the regulatory powers conferred by Article 99 of the Law on Supervision and Regulation of the Financial System,

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 3 of 17 CNBCR-02/2022 NRP-32 TECHNICAL STANDARDS ON CYBERSECURITY MEASURES IN DIGITAL CHANNELS Approval: 21/02/2022 Validity: 8/03/2022 AGREES to issue the following: TECHNICAL STANDARDS ON CYBERSECURITY MEASURES IN DIGITAL CHANNELS

CHAPTER I OBJECT, SUBJECTS, AND TERMS

Object Art. 1.- The object of these Standards is to regulate the cybersecurity measures of financial entities, through which information of the products and financial services that said entities offer to their clients in digital channels is collected, processed, transmitted, and stored. Likewise, the terms used in these Standards will have the same meaning established in the "Technical Standards for Information Security Management" (NRP-23).

Subjects Art. 2.- The subjects obligated to comply with the provisions established in these Standards are: a) Banks constituted in El Salvador; b) Branches of foreign banks established in El Salvador; c) Savings and credit societies; d) Cooperative banks; (2) e) Federations formed by cooperative banks and also by savings and credit societies regulated by the Law on Cooperative Banks and Savings and Credit Societies; and (2) f) Investment banks, their offices abroad, and their subsidiaries. (2)

Terms Art. 3.- For the purposes of these Standards, the terms indicated below have the following meaning: a) Affiliation or subscription: incorporation of products and financial services, by the client, for the purpose of carrying out operations or transactions in digital channels; b) Authentication: set of technological techniques and procedures used to verify the identity of a user of digital channels (1); c) Dynamic authentication: authentication method, which consists of generating a code for an electronic payment medium, different in each transaction, and signing it with its private key; d) Static authentication: method consisting of generating a code for an electronic payment medium, in the personalization phase of this, which is recorded in its chip and never changes. It can be validated by a terminal; e) Mobile Banking: digital channel that uses a mobile device to access services and financial transactions associated with deposit accounts, credit lines, or simplified requirement savings accounts; f) Internet Banking: digital channel associated with deposit accounts, credit lines, or simplified requirement savings accounts, which uses a transactional portal to access services and financial transactions; g) Telephone Banking: digital channel associated with deposit accounts, credit lines, or simplified requirement savings accounts, which uses a telephone device to access services and financial transactions through calls to telephone service centers; h) Digital Channel(s): medium that allows the carrying out of transactions, the provision of financial services, and the exchange of information, such as ATMs, point of sales (POS, by its acronym in English), telephone banking, Interactive Voice Response (IVR, by its acronym in English), internet banking, mobile banking, among others; i) Access Key (PIN): personal identification number used to access services and financial operations through digital channels; j) Dynamic keys: are one-time cryptographic keys, formed through a random sequence; k) Client: natural or legal person who maintains a contractual relationship with the Entity for the provision of one or more passive or active operations; l) Password or key: protected string of characters used to authenticate the identity of a user to authorize access to the use of digital channels; m) Sensitive Data: confidential data of the client or user of electronic banking, such as: account number; personal identification number; client keys; card number; card security code; n) Disaffiliation: process by which clients request entities to disincorporate the products and services offered by them, through digital channels; o) Self-service devices: electronic equipment offered to clients to carry out banking operations that do not involve cash, such as kiosks, POS, among others; p) Entity/entities: subjects obligated to comply with these Standards according to Article 2 thereof; q) Additional Factor: is the second factor or group of authentication factors that must be requested to the client;

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 4 of 17 CNBCR-02/2022 NRP-32 TECHNICAL STANDARDS ON CYBERSECURITY MEASURES IN DIGITAL CHANNELS Approval: 21/02/2022 Validity: 8/03/2022 r) Authentication Factor: information used to verify the identity of a service or a person; s) Base Factor: is the minimum factor required to perform the initial authentication of the client; t) Identification: validation of the client's identity for the use of digital channels, through the use of data and information known by both the entity and the client; u) Threat Intelligence: Information about threats that has been added, transformed, analyzed, interpreted, or enriched to provide the necessary context for decision-making processes; (1) v) IVR: (Interactive Voice Response, by its acronym in English) is a telephone system capable of receiving a call and interacting with the human through voice recordings and the recognition of simple responses; (1) w) Repealed; (1) x) Electronic communication medium: electronic medium used for the transmission of messages from the entity to the client, or vice versa; (1) y) Non-repudiation: security method that allows proving the participation of the parties in a communication, contemplating the following 2 aspects: i. Non-repudiation at origin: the sender cannot deny that they sent it because the recipient has proof of the sending; and ii. Non-repudiation at destination: the receiver cannot deny that they received the message because the sender has proof of the reception. The origin or reception of a specific message must be verifiable by a third party of trust; (1) z) Transactional Profile: set of characteristics associated with the transactional behavior of a client, according to the systematic analyses performed by the entity, to protect their clients; (1) aa) Payment Schedules: is the authorization by the client for automatic debit in their bank accounts or authorization of charges on their credit cards; (1) bb) Superintendence: Superintendence of the Financial System; (1) cc) Token: electronic device used to facilitate the authentication process. It can be used for the generation of one-time passwords; as well as, for storing passwords, electronic signatures, or biometric data of the person; and (1) dd) Transactions: services and financial operations carried out through digital channels. (1)

CHAPTER II ON CYBERSECURITY IN INFORMATION SYSTEMS

Cybersecurity Measures Art. 4.- Entities must implement or update tools and mechanisms to monitor networks and other technological infrastructure that allows timely detection of security or cybersecurity events, unusual activity or behaviors, or lateral movements. These must also include threat intelligence to seek to stay informed about threats and indicators of compromise from other reliable sources.

Vulnerability Management Art. 5.- Entities must have processes for vulnerability management that consider the identification, evaluation, treatment, and communication of security measures in technological infrastructure, through the execution of penetration or intrusion tests and vulnerability scans. All security gaps must be remediated or mitigated, not only those classified as critical and high risk. Likewise, they must establish a methodology to remediate all security gaps and not only those classified as critical and high risk. The latter must be remediated on a priority basis, establish implementation plans, and carry out respective follow-up for the rest of the vulnerabilities, all of which must be duly documented.

Patch Management Art. 6.- Entities must have agile processes to acquire, test, and install patches for components of technological infrastructure, so that they remain updated; and avoid the use of applications, operating systems, and database managers without the support of the manufacturer or provider of security updates.

Multi-factor Authentication Art. 7.- Entities must implement the use of multi-factor authentication in any user account that accesses through the Internet, and privileged accounts, including those that have a trust relationship, so that two or more additional layers of security are added to each online platform accessed. All related to the multi-factor authentication of clients in digital channels is regulated in Chapter III of these Standards.

Identity Spoofing Protection Tools Art. 8.- Entities must have tools to prevent identity spoofing against threats based on phishing emails, spam, spear-phishing, among others, and must consider the suitability of these tools, so that they are consistent with the size of the entity. Entities must have constant training programs on this type of threat for employees, emphasizing those who perform customer service functions. Art. 9.- Entities must carry out financial education campaigns in which clients are made aware of the cybersecurity measures they must apply in the different digital channels they access. Art. 10.- Entities must notify their clients of the official means through which they will communicate the products or services they offer.

Antimalware Tools Art. 11.- Entities must have antivirus or antimalware programs and review them regularly to ensure they are adequate for their purpose, and are capable of detecting new threats, as well as reviewing configuration settings to guarantee the expected level of protection.

Mobile Device Management Art. 12.- Entities must implement mobile device management solutions to ensure that entity data is protected.

Data Loss Prevention Tools Art. 13.- Entities must have data loss prevention tools to have visibility into such events, so as to strengthen the detection and prevention of data exfiltration.

Encryption Art. 14.- Entities must encrypt critical information at rest or in transit, even in removable and mobile storage devices, ensuring that the protocols used are secure.

AAA Protocols (Authentication, Authorization, and Accounting) Art. 15.- Entities must have in their technological infrastructure protocols that perform the functions of user authentication; authorization and use of resources or services; and logging of user activity for respective follow-up.

Asset Management Art. 16.- Entities must keep updated the inventory of critical information assets and identify the data and associated technology to prioritize actions, in concordance with what is regulated in the "Technical Standards for Information Security Management" (NRP-23).

Logging and Follow-up Art. 17.- Entities must adapt systems and other components of technological infrastructure to generate the capacity to have a record of information that allows active detection and investigation of incidents, ensuring that activity logs are available for analysis when necessary, in concordance with what is regulated in the "Technical Standards for Information Security Management" (NRP-23).

Cybersecurity Incident Response Art. 18.- Entities must have response plans to mitigate the impact in the event of a cybersecurity incident. These plans must be tested to prove response capacity and identify gaps timely, in concordance with what is regulated in the "Technical Standards for Information Security Management" (NRP-23).

CHAPTER III ON THE AFFILIATION, IDENTIFICATION, AND AUTHENTICATION OF CLIENTS THROUGH DIGITAL CHANNELS

Art. 19.- Entities that carry out operations and provide financial services through digital channels must inform their clients in writing or through electronic means, at the time of activating the use of the digital channel for the first time, at least the following: a) Services offered and responsibilities for their use; b) Procedures for affiliation, cancellation, suspension, and reactivation of the service; c) Amount and transaction limits to be carried out in determined periods; d) Commissions and fees for use, with their respective description; e) Inherent risks for its use; f) Procedure to report any irregularity or potentially unrecognized or unauthorized activity that has been detected, whether by the client or by the entity; g) Procedure for the attention of client inquiries and complaints; h) Assumption of responsibilities by the client and the entity in situations of fraud; and i) Advice for adequate use by the client.

Art. 20.- Regarding affiliation to financial products or services through digital channels, such as internet banking and/or mobile banking, entities may implement the acceptance of electronic contracts, using authentication factor category 2 referred to in Article 21 of these Standards. The above will be considered as the confirmation and authorization of use of services in digital channels.

Art. 21.- Entities must use multiple authentication factors to verify the identity of their clients to carry out operations through digital channels. Said authentication factors will be, as a minimum, 3, within the following: Authentication Factor Category 1: Composed of information obtained from the client's contract and the use of products, services, or operations carried out by them through various channels. This information will be used by applying questions to the client through the Telephone Banking channel or other digital medium available to the entity. For this type of factor, entities must do the following: a) Define in advance the questionnaires that will be applied for the identification of clients and modify the questions contained in the questionnaires at least once a year; b) Establish random generators of the questions in the questionnaires; and c) When an operator is involved, they must not know the answers in advance for the identification of the client, which must be validated using computer systems. Authentication Factor Category 2: Composed of passwords that only the client knows and enters through an access mechanism or device, which must meet, at least, the following characteristics: a) Its minimum length and composition must be according to the following: i. Four characters, for services offered through ATMs, point of sales, Telephone Banking, and IVR service; ii. Eight characters

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 5 of 17 CNBCR-02/2022 NRP-32 TECHNICAL STANDARDS ON CYBERSECURITY MEASURES IN DIGITAL CHANNELS Approval: 21/02/2022 Validity: 8/03/2022

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 6 of 17 CNBCR-02/2022 NRP-32 TECHNICAL STANDARDS ON CYBERSECURITY MEASURES IN DIGITAL CHANNELS Approval: 21/02/2022 Validity: 8/03/2022

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 7 of 17 CNBCR-02/2022 NRP-32 TECHNICAL STANDARDS ON CYBERSECURITY MEASURES IN DIGITAL CHANNELS Approval: 21/02/2022 Validity: 8/03/2022

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 8 of 17 CNBCR-02/2022 NRP-32 TECHNICAL STANDARDS ON CYBERSECURITY MEASURES IN DIGITAL CHANNELS Approval: 21/02/2022 Validity: 8/03/2022

Alameda Juan Pablo II, between 15 and 17 Av. Norte, San Salvador, El Salvador. Tel. (503) 2281-8000 www.bcr.gob.sv Page 9 of 17 CNBCR-02/2022 NRP-32 TECHNICAL STANDARDS ON CYBERSECURITY MEASURES IN DIGITAL CHANNELS Approval: 21/02/2022 Validity: 8/03/2022