Publications of the part

The National Bank of Moldova (NBM) intends to approve the Regulation on minimum requirements for ICT and information security risk management.

The National Bank of Moldova (NBM) intends to approve the Regulation on minimum requirements for ICT and information security risk management.

This is stipulated in the draft of a relevant decision of the Executive Committee of the National Bank, which NBM has submitted for public consultation. The mentioned draft regulation aims at ensuring that banks have an adequate internal structure for information and communication technology (ICT) risk management and information security, coordinated with the general business strategy and that internal management processes are adequately set up for the bank's ICT systems and adequately protect the bank's ICT systems. The Regulation also adjusts the NBM requirements to the European Business Association (EBA) Guidelines on ICT and security risk management and to international standards in the field. In the same context, the Regulation imposes certain requirements to be met by banks in order to be able to react to new threats in the field and to ensure an efficient banking business continuity management. The draft Regulation on minimum requirements for ICT and information security risk management contains requirements for the management, strategy, internal structure of ICT and information security; minimum requirements for ICT operations and ICT incident management; minimum requirements for the organization and stages of the process of ensuring business continuity in banks; requirements for duplication of critical equipment and key elements of the banking infrastructure; data retention requirements for backups, audit logs, video surveillance systems, and email service; requirements for annual testing of the security, availability and continuity of critical ICT systems/services; the requirement to inform the NBM at the end of each year about incidents during the year, the issuance of a SWIFT assessment report and, where applicable, the issuance of a bank assessment report in accordance with the PCI-DSS standard. Recommendations on the draft decision of the NBM are accepted until 11 April. //22.03.2022 - InfoMarket.

News on the subject