Customers’ Data: Bank Directors Will Be Held Responsible For Breach – CBN

Must Read

SAN FRANCISCO, June 28, (THEWILL) – The Central Bank of Nigeria (CBN) has declared that Bank Directors will henceforth be responsible for the protection and security of customers’ data against e-fradusters,

The new rule followed the sophistication and rise in the number of cyber-security threats against Deposit Money Banks (DMBs) and Payment Service Providers (PSPs) which require strengthening their cyber defences to remain safe and sound.

In a circular released by the CBN, titled: Risk-based Cyber-security Framework for Deposit Money Banks, signed by K.O Balogun for CBN Director of Banking Supervision, the regulator said provision of oversight and leadership and resources to ensure that cyber-security governance becomes an integral part of corporate governance, rests with the Board of Directors.

Ask ZiVA 728x90 Ads

The CBN also directed the boards to henceforth ensure that cyber-security is completely integrated with business functions and, well managed across the DMB/PSP.

“The Board of Directors through its committees will now have overall responsibility for the DMB/PSP’s cyber-security programme. It will provide leadership and direction for effective conduct of the processes,” it said.

“The Board will ensure that cyber-security governance is integrated into the organisational structure and relevant processes.

“Also, the board will ensure that cyber-security processes are conducted in line with business requirements, applicable laws and regulations while ensuring security expectations are defined and met across the DMB/PSP.

“The Board will now hold Senior Management responsible for central oversight, assignment of responsibility, effectiveness of the cyber-security processes and shall ensure that the audit function is independent, effective and comprehensive.

“Besides, the board will be responsible for all cyber-security governance documents such as cyber-security strategy, framework and policies and ensure alignment with the overall business goals and objectives.

“Also, the board will, on a quarterly basis receive and review reports submitted by Senior Management. The report shall detail the overall status of the cyber-security programme to ensure that board- approved risk thresholds relating to cyber-security are being adhered to.

“Boards are also mandated to appoint or designate a qualified individual as the Chief Information Security Officer (CISO) who shall be responsible for overseeing and implementing its cyber-security programme.”

THEWILL APP ADS 2
- Advertisement -spot_img
- Advertisement -spot_img
Latest News

UEFA Refuses To End FIFA World Cup Boycott Despite Infantino’s U-Turn

UEFA has confirmed it will continue its boycott of FIFA's men's and women's World Cups despite Gianni Infantino...
- Advertisement -spot_img

More Articles Like This

- Advertisement -spot_img