REGULATION No 02/2018 OF 24/01/2018 ON CYBERSECURITY
This regulation says its purpose is to set minimum prudent standards for banks to protect against cybersecurity threats and to promote protection of customer information and banks’ information technology systems.
AI-assisted research synopsis — verify against the official legal text below.
- Jurisdiction
- Rwanda
- Instrument
- Regulation
- Citation
- 02/2018 OF 24/01/2018
- Status
- Not in force
- Version
- Undated source snapshot
- Language
- mul
- Updated
- Official source
- View official record ↗
Statute overview
About this statute
This regulation says its purpose is to set minimum prudent standards for banks to protect against cybersecurity threats and to promote protection of customer information and banks’ information technology systems. This article defines key terms used in the regulation. Banks licensed by the Central Bank must keep their primary data in Rwanda. Banks must set up cybersecurity governance, including board responsibility, an IT committee, and an IT security unit. Banks must maintain a cybersecurity strategy and program and provide related documents to Banki Nkuru when requested.
Search within this statute
Search all stored provisions in this version.
Legal text
Provisions of REGULATION No 02/2018 OF 24/01/2018 ON CYBERSECURITY
Showing 23 of 23
- 1 Verify source ↗
Icyo aya mabwiriza agamije
AI-assisted research summary: This regulation says its purpose is to set minimum prudent standards for banks to protect against cybersecurity threats and to promote protection of customer information and banks’ information technology systems.
Ingingo ya mbere: Icyo aya mabwiriza agamije Article one: Purpose Article premier: Objet Ingingo ya mbere: Icyo aya mabwiriza agamije Article one: Purpose Article premier: Objet Aya mabwiriza agamije : This regulation aims at : Le présent règlement vise à: 1° gushyiraho ibigenderwaho by’ibanze ku mabanki hagamijwe gukumira ibishobora umutekano w’ibijyanye guhungabanya itangazabumenyi n’ikoranabuhanga mu n’itumanaho; no 1° establishing minimum prudent standards to banks for their protection against cybersecurity threats ; and 1° établir pour des banques des normes de les les menaces de minimales pour prudentiels protéger contre cybersécurité ; et 2° guteza imbere uburyo bwo kurinda amakuru ku bakiriya kimwe n’uburyo guhanahana bw’ikoranabuhanga amakuru bukoreshwa n’amabanki. mu 2° promoting the protection of customer information as well as the information technology systems of banks 104 2° promouvoir la protection des informations des clients ainsi que des technologies systèmes d’informations des banques. de Official Gazette n° 6bis of 05/02/2018 - 2 Verify source ↗
Ibisobanuro by’amagambo
AI-assisted research summary: This article defines key terms used in the regulation.
Ingingo ya 2: Ibisobanuro by’amagambo Article 2: Definition of terms Article 2: Définition des termes Ingingo ya 2: Ibisobanuro by’amagambo Article 2: Definition of terms Article 2: Définition des termes Muri aya mabwiriza, amagambo akurikira asobanura: In this regulation, the following words and expressions shall mean: Dans le présent règlement, les termes et expressions suivants signifient: 1° ukorana n’ikigo: Umuntu uwo ari we wese ugenzura, ugenzurwa cyangwa ugenzurirwa hamwe n’undi muntu. Muri iki gisobanuro, kugenzura bisobanura kugira ububasha mu buryo buziguye cyangwa butaziguye bwo gutanga icyerekezo cyangwa kugira ijambo icyerekezo ku rikomeye mu gutanga micungire cyangwa kuri politiki z’umuntu byaba binyuze ku kuba afite ububiko bw’uwo muntu cyangwa mu bundi buryo ; 2° ukoresha bukoresha uburyo ikoranabuhanga ubyemerewe: umukozi uwo ari we wese, ufitanye amasezerano na banki, uyihagarariye cyangwa undi muntu uwo ari we wese ugira uruhare mu bikorwa by’ubucuruzi bya banki kandi akaba ku buryo bukoresha yemerewe kugera ikoranabuhanga no ku makuru yayo kimwe no kubikoresha ; 3° ikibazo cy’umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho: igikorwa icyo ari cyo cyose cyangwa kugerageza gukora igikorwa cyaba cyagezweho cyangwa kitagezweho cyo guhungabanya kugera utabyemerewe, , 1° affiliate: any person that controls, is controlled by or is under common control with another Person. In this definition the possession, direct or indirect, of the power to direct or cause the direction of the management and policies of a Person, whether through the ownership of stock of such Person or otherwise ; control means 2° authorized User: any employee, contractor, agent or other person that participates in the business operations of a bank and is authorized to access and use any Information Systems and data of the bank ; 1° affilié : toute personne qui contrôle, est contrôlée par ou se trouve sous le contrôle commun avec une autre personne. Aux fins de cette définition, contrôle signifie la possession directe ou indirecte du pouvoir de diriger ou d’influencer la direction de la gestion et des politiques d’une personne que ce soit à travers la possession des actions d’une telle personne ou d’une autre manière que ce soit ; 2° utilisateur autorisé: tout employé, contractant, agent ou toute autre personne qui participe aux opérations commerciales d’une banque et est autorisée à accéder aux systèmes d’informations et des données de la banque et à les utiliser ; 3° cybersecurity incident: any act or attempt, successful or unsuccessful, to gain unauthorized access to, disrupt or misuse an Information System or information stored on such Information System. 3° incident de cybersécurité: toute acte ou tentative ayant réussi ou non visant à avoir accès non autorisé, perturber ou abuser d’un système d’informations ou de l’information stockée sur ce système. 105 Official Gazette n° 6bis of 05/02/2018 cyangwa gukoresha nabi uburyo bukoresha ikoranabuhanga cyangwa amakuru abitswe kuri bene ubwo buryo. bw’ibanga bukoresha 4° uburyo ikoranabuhanga: Uburyo bw’ibikenerwa byifashishwa mu guhanahana amakuru ikoranabuhanga hifashishijwe bwatunganyirijwe gukusanya, gutunganya, kubika, gukoresha, guhanahana, gusakaza amakuru mu buryo cyangwa kugira n’uburyo bw’ikoranabuhanga bwihariye kugenzura bukoreshwa mu nganda/itunganya ry’ibintu binyuranye, gushyiraho imirongo ya telefoni, uburyo bwo guhamagarana kuri telefoni ikigo kihariye, kimwe n’uburyo bwo kugenzura ibidukikije. kimwe bwo nk’uburyo use, 4° information System: a discrete set of electronic resources information organized for the collection, processing, sharing, maintenance, dissemination of electronic information, as well as any specialized as system systems, industrial/process telephone switching and private branch exchange systems, and environmental control systems. disposition controls such or 4° iystème d’information: un ensemble distinct de ressources électroniques d’information organisées pour la collecte, le traitement, la maintenance, l’utilisation, le partage, la diffusion ou la disposition d’informations électroniques ainsi que tout système spécialisé tel que les systèmes de industriels/processus, contrôle commutation les systèmes d’autocommutateurs téléphoniques privés , et des systèmes de contrôle de l’environnement. téléphonique ainsi 5° gusuzuma umwirondoro hagendewe ku bintu byinshi: gusuzuma umwirondoro w’umuntu ugendeye nibura ku bwoko bubiri bw’ibintu byifashishwa mu kumenya uwo ari we: 5° multi-Factor authentication: authentication through verification of at least two of the following types of authentication factors: 5° authentification multi-factorielle: authentification par vérification d’au moins deux des types de facteurs d’authentification suivants: kuba azi a) knowledge factors, such as a a) ibyo agomba nk’ijambobanga; b) ibyo agomba nk’akarango ubutumwa igendanwa; cyangwa kuri kuba afite cyangwa telefoni password; b) possession factors, such as a token or text message on a mobile phone; or 106 a) facteurs de connaissance, tel un mot de passe ; b) facteurs de possession, tel un jeton d’authentification text un message ou téléphonique un sur téléphone mobile ; ou c) ibyerekeranye n’imiterere y’ibiranga umuntu nk’ibiranga imiterere y’umubiri. 6° amakuru atari rusange: amakuru ayo ari yo yose abantu bose badashobora kugeraho abitswe mu buryo bw’ikoranabuhanga kandi: a) akaba afitanye isano n’ibikorwa by’ubucuruzi bya banki ku buryo kuyahindura mu buriganya, cyangwa kuyageraho hanze, kuyasakaza cyangwa nta kuyakoresha burenganzira byagira ingaruka mbi ku bucuruzi, cyangwa ku ibikorwa mutekano wa banki; izina b) amakuru ayo ari yo yose yerekeranye rye, n’umuntu biturutse ku nomero ye, ikimenyetso cye bwite, cyangwa ikindi kintu kimuranga gishobora gukoreshwa mu kumenya uwo muntu hakoreshejwe kimwe ibi bintu cyangwa byinshi muri nomero bikurikira: y’ubwiteganyirize ye, (ii) nomero y’uruhushya rwo gutwara ibinyabiziga ye y’ikarita ndangamuntu ku badafite uruhushya rwo gutwara ibinyabiziga, (iii) nomero ya konti, nomero y’ikarita yo yemera kubikuriza amafaranga cyangwa nomero (i) Official Gazette n° 6bis of 05/02/2018 c) inherence factors, such as a biometric characteristic. c) facteurs d’inhérence e, tel un caractère biométrique. 6° nonpublic information: all electronic is not Publicly information Available Information and is: that a) business related information of the bank, the tampering with which, or disclosure, unauthorized access or use of which, would cause a material adverse the impact business, operations or security of the bank; to b) any information concerning which individual an because of name, number, personal mark, or other identifier can be used to identify such individual, in combination with any one or more of the following data elements: (i) social (ii) security drivers’ license number or non-driver identification card number, (iii) account number, credit or debit card number, (iv) any security number, 107 6° information non publique: toute information électronique qui n’est pas disponible au public et qui est : a) l’accès l’information commerciale de la banque, dont la falsification ou la ou divulgation, autorisés l’utilisation non impact négatif auraient un sérieux les l’activité, sur opérations ou la sécurité de la banque; de b) toute information concernant un individu qui du fait du nom, du numéro, la marque personnelle, ou d’un autre signe d’identification peut être utilisée pour identifier cet individu en ou combinaison plusieurs de données suivants : : (i) le numéro de la sécurité sociale, (ii) le numéro du permis de conduire ou carte le d’identification non conducteur, (iii) le numéro de compte, le numéro de la carte de un éléments la du numéro avec des de Official Gazette n° 6bis of 05/02/2018 access code, code or password that would permit access to an individual’s financial account, or (v) biometric records; passe crédit ou de débit, (iv) tout code de sécurité, code d’accès ou mot de permettrait qui d’accéder à un compte financier d’un individu’ ou (v) les données biométriques ; amafaranga iy’ikarita yo inguzanyo cyangwa kubikiriza itemera inguzanyo, (iv) ubundi buryo bwose bwo kurinda umutekano, uburyo bwo kugera cyangwa ijambobanga rituma umuntu agera ku makuru yamufasha kugera kuri konti y’umuntu ku giti cye, cyangwa (v) amakuru ku miterere y’umubiri; ku makuru (i) kose cyangwa c) amakuru ayo ari yo yose, usibye imyaka cyangwa igitsina uko yaba ateye uburyo abitswemo, yateguwe n’umukozi wo mu rwego rw’ubuvuzi yerekeranye n’umuntu ku giti cye avuga ku byerekeranye n’ubuzima bw’umubiri we , ubuzima bwo mu mutwe cyangwa imyitwarire ye mu gihe cyahise, ubungubu cyangwa igihe kizaza cyangwa uburwayi bw’umuntu ku giti cye cyangwa bw’umwe mu bagize umuryango we (ii) itangwa rya serivisi z’ubuzima ku muntu uwo ari we wese, cyangwa (iii) ubwishyu bwa serivisi z’ubuzima ku muntu uwo ari we wese. 7° kugerageza kwinjira nta burenganzira: uburyo bukoreshwa mu kugerageza aho isuzuma bagerageza gukwepa abakora umutekano ibigize cyangwa ikoranabuhanga w’uburyo bukoresha kuganza or provider c) any information or data, except age or gender, in any form or medium created by or derived from a health care an individual and that relates to (i) the past, present or future physical, mental or behavioral or condition of any individual or a member of the individual's family, (ii) the provision of health care to (iii) individual, or any payment for the provision of health care to any individual. health 7° penetration a Testing: test methodology in which assessors attempt to circumvent or defeat the security features of an information system by attempting penetration of databases or 108 c) toute information ou données, à l’exception de l’âge ou du genre, sous quelque forme ou support que ce soit, créés par ou provenant d’un prestataire de services de santé ou d’une personne et qui sont relatives (i) à la santé ou l’état physique, mental ou comportemental passé, toute présent ou personne ou d’un membre de safamille, ou (ii) à la fourniture de soins de santé à tout individu, ou (iii) au paiement de soins de santé à tout individu. futur de 7° test d’intrusion: une méthodologie de test dans laquelle les évaluateurs tentent les de contourner ou de déjouer d’un de caractéristiques système d’information en essayant de sécurité Official Gazette n° 6bis of 05/02/2018 bagerageza kwinjira mu bubiko bw’amakuru cyangwa ahakorerwa igenzura binjiriye imbere cyangwa inyuma y’uburyo bukoresha ikoranabuhanga bukoreshwa na banki. controls from outside or inside the bank’s information systems. pénétrer les banques de données ou les contrôles de l’extérieur ou à l’intérieur des Systèmes d’Informations de la banque. 8° amakuru rusange: amakuru ayo ari yo yose banki ishobora gutekereza ko abantu bose bashobora kumenya mu buryo bwemewe n’amategeko : ni ukuvuga amakuru aturuka mu nzego za Leta cyangwa mu nzego z’ibanze; ibitangazamakuru bigera ku bantu agomba benshi; gutangarizwa hakurikijwe amategeko. cyangwa amakuru rubanda bwo ibintu 9° isuzuma ry’umwirondoro rishingiye ku byateza ingorane: Uburyo ubwo ari bwo bwose umwirondoro gusuzuma bushingiye ku ngorane zishobora kuba cyangwa butahura impinduka mu bijyanye n’imikoreshereze isanzwe kandi bugasaba ko habaho irindi genzura ry’ibiranga umuntu igihe ibyo bintu izo mpinduka bidasanzwe zigaragaye nko kumubaza ibibazo byo kureba niba uwo muntu ari we koko. bidasanzwe cyangwa is to believe 8° publicly Available Information: any information that a bank has a reasonable lawfully made basis available to the general public from: the Government or local government records; widely distributed media; or disclosures to the general public that are required to be made by the law. 9° risk-based authentication: any risk- based system of authentication that detects anomalies or changes in the normal use patterns of a Person and requires additional verification of the Person’s identity when such deviations or changes are detected, such as through the use of challenge questions. 8° informations publiques: toute information dont la banque a toute raison de croire qu’elle est légalement disponible au grand public à partir : des archives de l’Etat ou d’une collectivité locale; des organes médiatiques de large diffusion; ou des révélations au grand public qui sont exigées par la loi. 9° authentification basée sur le risque: tout système d’authentification basée sur le risque qui détecte des anomalies ou des changements dans la manière d’utilisation normale d’une personne et vérification qui supplémentaire de la personne lorsque de telles déviations ou changements sont détectés notamment par le biais de l’utilisation des questions secrètes. l’identité de requiert une 10° undi muntu utanga serivisi: Umuntu (i) utari usanzwe akorana na banki, (ii) uha banki serivisi, kandi (iii) ufata neza, utunganya cyangwa wemerewe kugera ku makuru atari rusange binyuze muri serivisi ayiha. 10° third party service provider(s): a Person that (i) is not an Affiliate of the bank, (ii) provides services to the bank, (iii) maintains, processes or and to is permitted access otherwise 10° tiers prestataire (s) de services: une personne qui (i) n’est pas un affilié de la banque, (ii) donne des services à la banque, et (iii) maintient, traite ou est autrement autorisée d’accéder aux 109 Official Gazette n° 6bis of 05/02/2018 Nonpublic provision of services to the bank. Information through its informations non publiques par le biais de prestation de services à la banque. - 3 Verify source ↗
Kurinda amakuru y’amabanki
AI-assisted research summary: Banks licensed by the Central Bank must keep their primary data in Rwanda.
Ingingo ya 3: Kurinda amakuru y’amabanki Article 3: Banking data protection Article 3: Protection de données bancaires UMUTWE WA II: IBISABWA MU MATEGEKO CHAPTER REQUIREMENTS II: REGULATORY CHAPITRE II: REGLEMENTAIRES EXIGENCES Ingingo ya 3: Kurinda amakuru y’amabanki Article 3: Banking primary data location Article 3: Protection de données bancaires Banki iyo ariyo yose yemewe na Banki Nkuru itegetswe kubika amakuru yayo y’ibanze ku butaka bwa Repubulika y’u Rwanda. Any bank lincensed by the Central Bank must maintain its primary data on the territory of the Republic of Rwanda. Toute banque agréer par la Banque Centrale doit maintainir ses données primaires sur le territoire de la République du Rwanda. UMUTWE WA II: IBISABWA MU MATEGEKO CHAPTER REQUIREMENTS II: REGULATORY CHAPITRE II: REGLEMENTAIRES EXIGENCES - 4 Verify source ↗
Inshingano z’Inama y’Ubutegetsi
AI-assisted research summary: Banks must set up cybersecurity governance, including board responsibility, an IT committee, and an IT security unit.
Ingingo ya 4: Inshingano z’Inama y’Ubutegetsi n’Ubuyobozi bukuru mu rwego rw’umutekano w’ibijyanye mu itangazabumenyi n’itumanaho n’ikoranabuhanga Article 4: Board and Senior Management Cybersecurity Responsibilities Article 4: Les responsabilités du conseil d’administration et de la direction générale en matière de cybersécurité Ingingo ya 4: Inshingano z’Inama y’Ubutegetsi n’Ubuyobozi bukuru mu rwego rw’umutekano w’ibijyanye mu itangazabumenyi n’itumanaho n’ikoranabuhanga Article 4: Board and Senior Management Cybersecurity Responsibilities Article 4: Les responsabilités du conseil d’administration et de la direction générale en matière de cybersécurité (4.1) Imiyoborere y’umutekano w’amakuru ni inshingano y’Ubutegetsi y’Inama n’ubuyobozi bukuru. Buri banki igomba kugira uburyo rusange bw’imiyoborere y’umutekano w’amakuru bugizwe n’ibi bikurikira: (4.1) Information Security Governance must be the responsibility of the Board of Directors and Senior Management. Each bank must have a comprehensive information governance security framework consisting of the following: a) ingamba z’umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho n’intego z’ibikorwa ; zijyanye a) cybersecurity strategy linked with business objectives; (4.1) La Gouvernance de la sécurité de l’information est la responsabilité du la conseil d’administration et de direction générale. Chaque banque doit disposer d’une structure globale de gouvernance de l’information qui consiste de ce qui suit : a) une stratégie de cybersécurité ayant trait aux objectifs opérationnels; sécurité de la b) gahunda y’umutekano y’ibanze itanga igisubizo kuri buri cyiciro cy’ingamba, cy’igenzura n’icy’amabwiriza ; b) governing security program that address each aspect of the strategy, controls and regulations; b) un programme régissant la sécurité applicable à chaque aspect de la stratégie, des contrôles et du règlement ; 110 c) urutonde rwuzuye rw’ibigenderwaho muri buri uburyo kugira bukurikizwa n’imirongo ngenderwaho bijyanye na politiki iriho ; politiki ngo d) imiterere y’ikigo ikora neza izira kugongana kw’ inyungu bwite, ifite n’ibyangombwa ububasha byuzuye ; buhagije e) ibipimo n’uburyo bwo kugenzura ko amabwiriza yubahirizwa kimwe no kumenya uko abandi babona imikorere y’urwo rwego ndetse no gushyiraho ibyashingirwaho mu ifatwa ry’ibyemezo mu rwego rw’imicungire ; kugira komite Inzobere mu by’ikoranabuhanga ku rwego rw’Inama y’Ubuyobozi: Buri banki ishinzwe igomba ikoranabuhanga mu itumanaho ku rwego rw’Inama y’Ubuyobozi yayo kugira ngo iyigire inama ku byerekeranye n’icyerekezo rwego kigomba rw’Ikoranabuhanga mu itumanaho no gukora ishoramari muri urwo rwego ibikorera Inama y’Ubutegetsi. gufatwa mu (4.2) Official Gazette n° 6bis of 05/02/2018 c) a complete set of standards for each policy to ensure procedures and guidelines comply with the policy; c) une série complète des normes de chaque politique visant à garantir la conformité des procédures et des Principes directeurs à la politique ; d) an effective organization structure void of conflict of interest with sufficient authority and adequate resources; e) metrics and monitoring processes to ensure compliance, feedback on effectiveness and provide the basis for appropriate management decisions; (4.2) Expertise at the Board Level: Each bank must have IT Committee at the Board level to give advice on strategic direction on IT and to review IT investments on Board's behalf. d) une structure organisationnelle efficace conflit d’intérêts avec une autorité suffisante et des ressources appropriées. dépourvue de en vue d’assurer e) des indicateurs et les processus de la contrôle conformité, sur l’efficacité et de fournir la base de prise de décisions de gestion appropriées ; réactions les (4.2) Expertise au niveau du conseil d’administration: Chaque banque doit disposer d’un comité chargé de l’ informatique conseil sein d’administration pour donner conseil sur l’ orientation stratégique en matière de la technologie d’information et pour revoir les investissements en la matière pour conseil le d’administration. compte du du (4.3) Ububasha bwa ishinzwe ikoranabuhanga n’itumanahano: komite ifite ububasha bukurikira: komite (4.3) Powers of IT the committee must have the following powers: Committee: (4.3) Compétences du Comité chargé de l’informatique: le comité dispose des compétences suivantes: a) kugenzura komite nyobozi ishinzwe a) perform oversight functions a) exercer des fonctions de 111 Official Gazette n° 6bis of 05/02/2018 Ikoranabuhanga n’itumanaho ; over the IT steering committee at managerial level ; supervision direction l’informatique ; du comité en charge de b) gukora amaperereza ku bikorwa muri b) investigate activities within this b) faire des investigations dans urwo rwego ; scope ; ce cadre ; c) gushakisha amakuru ku mukozi uwo ari c) seek information from any c) s’informer auprès de tout we wese ; employee ; employé ; d) gushaka ubufasha bwo mu rwego rw’amategeko n’urw’umwuga hanze y’ikigo ; e) kunoza uruhare rw’abo hanze bafite ubuzobere bukwiye mu gihe ari ngombwa ; f) gufatanya n’izindi komite z’Inama y’ubutegetsi n’ubuyobozi bukuru mu gutanga ibitekerezo, gusubiramo no sosiyete ingamba za guhindura rwego n’ingamba mu mu rw’ikoranabuhanga itangazabumenyi. zo (4.4) Gushyira mu bikorwa, kugerageza no kuvugurura ingamba zo kubungabunga umutekano bigomba w’amakuru gutegurwa nk’igice cy’ishyirwaho rya gahunda y’umutekano w’amakuru. Komite nshingwabikorwa n’Inama y’Ubuyobozi (4.4) d) obtain outside legal or professional advice ; d) obtenir conseils des juridiques ou professionnels de l’extérieur ; e) secure attendance of outsiders it with relevant expertise, considers necessary ; if f) work in partnership with other board committees and senior management to provide input, review and amend the aligned corporate and IT strategies. e) f) la présence des assurer personnes l’extérieur de ayant l’expertise voulue s’il le juge nécessaire ; et travailler en partenariat avec les autres comités du conseil d’administration la direction générale en vue de donner des commentaires, les revoir stratégies organisationnelles et informatique alignées. et modifier security strategy Information implementation, testing and reviews should be planned as part of the Information program development. The executive committee and the Board must review the security security 112 (4.4) La mise en œuvre, les tests et les révisions de la stratégie de la sécurité de l’information, doivent être planifiés l’élaboration du dans de sécurité programme l’information. Le comité exécutif et le le cadre de de la gusubiramo zifatanyije na ingamba zigomba z’umutekano serivisi ishinzwe umutekano w’amakuru, zikumva icyo ibisobanuro n’ingaruka, zikagira zivuga kuri buri gikorwa kigamije kugera ku ntego y’imikorere no guha umukuru wa serivisi ishinzwe umutekano w’amakuru igihe cyo kugira icyo avuga ku byavuzwe ingamba zisubiwemo no kuzoherereza zerekeranye komite n’ikoranabuhanga izunguraneho ibitekerezo, izinononsore inazemeze. ingamba ngo ifata serivisi Umukuru wa ishinzwe umutekano w’amakuru n’umuyobozi mukuru bagomba gusubiramo, kwemeza no gutangariza abo bireba inyandiko ya nyuma yerekeranye n’ingamba zafatwa rw’umutekano w’ikoranabuhanga. rwego mu Official Gazette n° 6bis of 05/02/2018 strategy with the IT Security Unit, understand the implications and effects, provide feedback on each initiative to achieve strategic objective and allow IT Security Unit time representative the comments and send the next version to the strategic committee for discussion, refinement and approval. respond the for to to conseil d’administration doivent revoir la stratégie de sécurité avec l’unité chargé de la sécurité des systèmes les d’information, en comprendre implications et les effets, donner des réactions sur chaque initiative visant à réaliser l’objectif stratégique et donner du temps au responsable de la sécurité des systèmes d’information pour réagir aux commentaires et d’envoyer la prochaine version au comité stratégique et pour approbation. finalisation discussion, The head of the information security or the Chief Executive Officer (CEO) must review, approve and communicate the final security strategy document to the intended audience. Le responsable de la sécurité des systèmes d’information et le directeur général doivent revoir, approuver, et communiquer le document final de la stratégie de sécurité au public visé. (4.5) Komite ishinzwe nyobozi ikoranabuhanga: Banki igomba kugira komite nyobozi ishinzwe ikoranabuhanga igizwe serivisi n’abahagarariye y’ikoranabuhanga, serivisi ishinzwe abakozi, n’inzego zishinzwe amategeko n’ubucuruzi. Inshingano zayo ni ugufasha ubuyobozi bukuru mu gushyira mu bikorwa ingamba mu n’umutekano byerekeranye w’ikoranabuhanga n’Inama Izo ngamba zikubiyemo y’ubuyobozi. ishyirwaho ry’ibyihutirwa mu ishoramari mu zemejwe (4.5) IT Steering Committee: The bank must have an IT Steering Committee with representatives from the IT, HR, legal and business lines. Its role must be to assist the Executive Management in implementing IT Security Strategy that has been approved by the Board. It includes prioritization of IT-enabled security the status of projects (including, resource conflict), monitoring service levels and investment, reviewing 113 composé (4.5) Le comité de direction chargé de l’informatique : La banque doit avoir un comité de direction chargé de l’informatique des représentants provenant des services informatique, ressources humaines, juridique et commercial. Son rôle est d’assister la direction exécutive dans la mise en œuvre de la stratégie de la sécurité des systèmes d’information qui conseil adoptée a stratégie d’administration. par Cette été le Official Gazette n° 6bis of 05/02/2018 improvements, IT service delivery and projects. rwego rw’umutekano w’ikoranabuhanga mu itangazabumenyi, gusubiramo imishinga (harimo no gukemura ibitumvikanwaho mu rwego rw’ibikenewe), kugenzura ibipimo n’ impinduka nziza bya serivisi , itangwa rya serivisi ndetse n’imishinga. z’ikoranabuhanga l’exam de comprend la définition des priorités des investissements en matière de la sécurité informatique, l’état des le conflit des projets (y compris ressources), le suivi des niveaux et des améliorations des services, la fourniture des services ainsi que des projets informatiques. Banki (ISU): n’ikoranabuhanga (4.6) Urwego rushyinzwe serivisi y’umutekano w’amakuru igomba gushyiraho umuntu w’inzobere ushinzwe gutegura ingamba na gahunda y’ umutekano w’ibijyanye mu itangazabumenyi n’itumanaho, gushyira mu bikorwa no kugenzura imikoreshereze y’iyo gahunda, gutanga inama ku bigomba gukorwa mu rwego rwo gukemura ibibazo bigenda bigaragara muri iyo gahunda no yayo bikorwa gushyira mu y’umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho. Urwego rugomba kandi guhora rukora isesengura n’ubugenzuzi k’umutekano w’amakuru mu ikoranabuhanga. politiki (4.6) a qualified IT Security Unit (ISU) : The bank must establish an IT Security Unit and individual designate responsible for designing cybersecurity strategy and program, implementing and overseeing the bank’s cybersecurity recommending program actions for addressing any noted program shortfalls and enforcing its cybersecurity policy. The unit must also perform regular information security internal assessments and audit. execution, et de concevoir programme le (4.6) L’unité chargé de la sécurité des systèmes d'information (ISU) : La individu banque doit désigner un la qualifié chargé stratégie de cybersécurité, de mettre en œuvre et de contrôler l’exécution du programme de cybersécurité de la banque, de recommander des actions pour remédier aux défaillances observées dans le programme et de mettre en œuvre sa politique de cybersécurité. L'unité doit également effectuer régulièrement des évaluations internes de sécurité de l'information et des audits. Inshingano za serivisi y’umutekano w’amakuru zishobora gukorwa na na banki, umwe mu bakorana nayo kimwe n’undi muntu utanga serivisi muri urwo rwego. Iyo ibisabwa muri urwo rwego byuzujwe hifashishijwe undi muntu utanga serivisi cyangwa ikigo gishamikiye kuri banki, banki igomba: The responsabilities of the Unit may be undertaken by the bank, one of its affiliates or a third party service provider. To the extent this requirement is met using a third party service provider or an affiliate, the bank must: Les responsabilités de l’unité chargé de la sécurité des systèmes d’information peuvent être employé par la banque, l’un de ses affiliés ou par un tiers prestataire de services. Si cette exigence est remplie en faisant recours à un prestataire de services ou un affilié, la banque doit : 114 a) kwishingira ko aya mabwiriza azubahirizwa; b) gushyiraho umwe mu bakozi bakuru ba banki ushinzwe kuyobora no kugenzura utanga serivisi; no c) gusaba utanga serivisi gukomeza gahunda y’umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho irinda banki nk’uko bisabwa muri aya mabwiriza. (4.7) Gutanga raporo: Ukuriye ISU atanga raporo k’Umuyobozi Mukuru cyangwa ku muyobizi ufite mu nshingano ze umutekano. ISU itanga raporo ku ngamba z’umutekano w’ibijyanye mu itangazabumenyi n’itumanaho rya banki no ishyirwa mu bikorwa rya gahunda ku y’umutekano; akagaragaza ibibazo bishobora kuvuka muri urwo rwego areba nibura ibi bikurikira: n’ikoranabuhanga Official Gazette n° 6bis of 05/02/2018 a) retain responsibility compliance with regulation; for this c) require b) designate a senior member the bank’s personnel of responsible for direction and oversight of the third party service provider; and third party service provider to maintain a cybersecurity program that protects the bank in the accordance requirements this regulation. with of the (4.7) Reporting: The head of the ISU must report the Chief Executive Officer (CEO) or the senior manager in charge of the cyber security. The Unit must the bank’s cybersecurity report on execution strategy material identifying cybersecurity risks and must consider at least the following: program emerging and a) retenir la responsabilité de présent au conformité règlement; b) désigner un cadre supérieur parmi son personnel chargé de diriger et de contrôler le tiers prestataire de services ; et c) exiger le tiers prestataire de services de maintenir un de programme cybersécurité qui protège la banque conformément aux exigences présent règlement. du de chargé superieur (4.7) Des rapports: Le chargé de ISU de chaque banque relève de CEO ou du la cadre sybersecurité. Il doit rendre compte de la stratégie de cybersécurité de la banque l’exécution du programme en et émergents risques identifiant importants en matière de cybersécurité et considérer au moins les aspects suivants : les a) Ibanga ku makuru atari rusange n’ubudakemwa n’umutekano w’uburyo bukoresha ikoranabuhanga bukoreshwa na banki; a) the confidentiality of nonpublic information and the integrity and security of the bank’s information systems; a) la confidentialité des informations non publiques et l’intégrité et la sécurité systèmes des d’information de la banque ; 115 Official Gazette n° 6bis of 05/02/2018 b) Politiki n’inzira zikurikizwa na banki mu rwego rw’umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho; b) the bank’s/ cybersecurity policies and procedures; b) les politiques et procédures de la de en matière banque cybersécurité ; c) Ibyateza ingorane kuvuka mu byigaragaza bishobora rwego rw’umutekano w’ibijyanye mu n’ikoranabuhanga itangazabumenyi n’itumanaho muri banki; c) emerging material cybersecurity risks to the bank; c) les risques sérieux et émergents de cybersécurité pour la banque; d) Ubushobozi muri rusange bwa gahunda y’umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho bwo kugera ku ngamba y’umutekano; na d) overall effectiveness of the bank’s cybersecurity program achieving security strategy; and d) l’efficacité globale du programme de cybersécurité de la banque dans la réalisation de la stratégie de sécurité ; et e) Ibikorwa bifatika by’umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho banki yagizemo uruhare mu gihe kirebwa n’iyo raporo. e) material events cybersecurity involving the bank during the time period addressed by the report ; e) des événements importants de cybersécurité qui ont impliqué la banque au cours de la période couverte par le rapport. article 4,5 et 6 du present règlement, suivant la date de sa publication au Journal Officiel de la République du Rwanda. - 5 Verify source ↗
Ingamba na gahunda y’umutekano
AI-assisted research summary: Banks must maintain a cybersecurity strategy and program and provide related documents to Banki Nkuru when requested.
Ingingo ya 5: Ingamba na gahunda y’umutekano w’ibijyanye mu itangazabumenyi n’itumanaho n’ikoranabuhanga Article 5: Cybersecurity program strategy and Article 5: Stratégie et programme de cybersécurité 101 Official Gazette n° 6bis of 05/02/2018 Ingingo ya 5: Ingamba na gahunda y’umutekano w’ibijyanye mu itangazabumenyi n’itumanaho n’ikoranabuhanga Article 5: Cybersecurity program strategy and Article 5: Stratégie et programme de cybersécurité (5.1) Banki igomba gushyiraho gahunda y’umutekano n’ikoranabuhanga mu n’itumanaho ubudakemwa, kurinda n’ukuboneka ingamba na w’ibijyanye itangazabumenyi amabanga, k’uburyo yo (5.1) The bank must maintain a cybersecurity strategy and program designed to protect the confidentiality, integrity and availability of the bank’s information systems. (5.1) La banque doit maintenir une stratégie et un programme de cybersécurité conçu confidentialité, pour la l’intégrité et la disponibilité des systèmes d’information de la banque. protéger 116 Official Gazette n° 6bis of 05/02/2018 bukoresha ikoranabuhanga bukoreshwa na banki. (5.2) (5.3) y’umutekano w’ibijyanye Ingamba itangazabumenyi n’ikoranabuhanga mu n’itumanahoitanga intango ya gahunda y’ibigomba gukorwa igizwe na gahunda y’umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho, ituma intego ziteganyijwe mu rwego rw’umutekano zishobora kugerwaho ishyizwe mu bikorwa. Ingamba na gahunda z’ibigomba uburyo gukorwa igenzura bishobora kwerekana urugero rw’ibyagezweho. zigomba kimwe guteganya n’ibipimo iyo na gahunda n’ikoranabuhanga y’umutekano Ingamba w’ibijyanye mu itangazabumenyi n’itumanahobigomba kuba bishingiye ku isuzuma ry’ibyateza ingorane ryakozwe na banki kandi bigomba kuba bigamije gukora nibura ibi bikurikira: a) gutahura no gusuzuma ibyateza y’umutekano rwego ingoranemu w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho by’imbere cyangwa yacyo kigo mu bishobora umutekano kubangamira cyangwa ubudakemwa bw’amakuru abitswe bukoresha ikoranabuhanga bukoreshwa na banki; hanze buryo mu program (5.2) The cybersecurity strategy must provide the basis for an action plan comprised of cybersecurity as implemented, achieve the planned security objectives. The strategy and action plans must contain provision for monitoring as well as defined metrics to determine the level of success. that (5.2) La stratégie de cybersécurité doit servir de base à un plan d’action comprenant un programme de cybersécurité qui, une fois mise en œuvre, permet de réaliser les objectifs de sécurité planifiés. La stratégie et les plans d’action doivent prévoir des dispositions pour le contrôle ainsi que des indicateurs définis en vue de déterminer le niveau de réussite. (5.3) The cybersecurity strategy and program must be based on the Bank’s risk assessment and designed to perform at least the following core cybersecurity functions: (5.3) La stratégie et le programme de cybersécurité doivent être basés sur l’évaluation des risques de la banque et être conçus pour remplir au moins les principales fonctions de cybersécurité reprises ci-après : a) threaten identify and assess internal and external cybersecurity risks that may security or the integrity of nonpublic information stored on the bank’s information systems; a) identification et évaluation des risques de cybersécurité internes et externes susceptibles de porter atteinte à la sécurité ou l’intégrité informations non publiques des stockées systèmes les sur d’information de la banque ; 117 Official Gazette n° 6bis of 05/02/2018 b) gukoresha ibikorwa remezo by’ubwirinzi no gushyira mu bikorwa politiki n’inzira zikurikizwa mu kurinda uburyo bukoresha ikoranabuhanga bukoreshwa na banki hamwe n’amakuru atari rusange abitswe kuri ubwo buryo, habuzwa kuyageraho burenganzira, nta kuyakoresha cyangwa kuyakoraho ibindi bikorwa by’ubugome; b) use defensive infrastructure and the implementation of policies and procedures to protect the bank’s the systems, information nonpublic information stored on those information systems, from unauthorized access, use or other malicious acts; and b) utilisation de et procédures l’infrastructure de défense et mise en œuvre des de politiques systèmes des protection d’information de la banque et des publiques informations stockées systèmes d’information contre tout accès ou utilisation non autorisés, ou d’autres actes malveillants ; non ces sur c) gutahura ibikorwa bihungabanya umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho ; c) detect cybersecurity incidents and regularly monitoring of abnormal and unauthorized access or use; c) détection cybersécurité; des incidents de d) gukemura ibibazo bikomoka ku bikorwa bihungabanya umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi byagaragaye cyangwa n’itumanaho byatahuwe mu rwego rwo kugabanya ubukana bw’ingaruka zabyo; e) gusana ibyangijwe n’ibikorwa ry’umutekano n’ikoranabuhanga mu no rya by’ihungabana w’ibijyanye itangazabumenyi n’itumanaho gusubukura serivisi zisanzwe; na ibikorwa n’itangwa d) respond to identified or detected cybersecurity incidents to mitigate any negative effects; e) recover from cybersecurity events and restore normal operations and services; and d) réaction aux incidents de cybersécurité identifiés ou détectés afin de mitiger tous les effets négatifs ; e) reprise après incidents de les cybersécurité et restauration du fonctionnement des opérations et des services ; et normal f) kuzuza inshingano zo gutanga raporo ziteganywa n’amabwiriza. f) fulfill applicable reporting obligations. regulatory 118 f) accomplissement des applicables en réglementaires obligations mstière d’information. Official Gazette n° 6bis of 05/02/2018 (5.4) Banki igomba gukora ibisabwa byose muri aya mabwiriza ishyiraho ingingo zikwiye za w’ibijyanye gahunda y’umutekano itangazabumenyi n’ikoranabuhanga mu n’itumanaho y’umuntu ukorana na banki; izo ngingo zipfa gusa kuba zuzuza ibisabwa muri aya mabwiriza bireba banki. (5.4) The bank must meet the requirement(s) of this regulation by adopting the relevant and applicable provisions of a cybersecurity program maintained by an affiliate, provided that such provisions satisfy this regulation, as applicable to the bank. requirements of the (5.4) La banque doit remplir les exigences du présent règlement en adoptant des dispositions appropriées et applicables d’un programme de cybersécurité maintenu par un affilié, pourvu que de telles dispositions satisfessent aux exigences du présent règlement autant que cela est applicable pour la banque. zose igomba (5.5) Banki Nkuru gushyikirizwa n’amakuru inyandiko gahunda n’ingamba yerekeranye y’umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho igihe ibisabye. kimwe na - 6 Verify source ↗
Politiki y’umutekano w’ibijyanye
AI-assisted research summary: Banks must keep an approved written cybersecurity policy and make relevant cybersecurity documents available to the Central Bank when requested.
Ingingo ya 6: Politiki y’umutekano w’ibijyanye n’ikoranabuhanga itangazabumenyi mu n’itumanaho Article 6: Cybersecurity Policy Article 6: Politique de cybersécurité Ingingo ya 6: Politiki y’umutekano w’ibijyanye n’ikoranabuhanga itangazabumenyi mu n’itumanaho (6.1) Banki igomba gushyira mu bikorwa no kubika politiki yanditse yemewe n’Inama y’Ubuyobozi igaragaza politiki yayo mu byerekeranye no kurinda uburyo bukoresha ikoranabuhanga kimwe n’amakuru atari rusange abitswe kuri ubwo buryo. Politiki y’umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho igomba gushingira ku isuzuma ry’ibyateza ingorane banki muri kandi ikagira icyo ivuga nibura kuri ibi bikurikira bijyanye n’ibikorwa bya banki: (5.5) All documentation and information relevant to the bank’s cybersecurity strategy and program must be made available to the Central Bank upon request. (5.5) Toute documentation et informations relatives à la stratégie et au programme de cybersécurité de la banque doivent être rendues disponibles à la Banque Centrale sur sa demande. Article 6: Cybersecurity Policy Article 6: Politique de cybersécurité (6.1) (6.1) The bank must implement and maintain a written policy approved by the bank board of directors, setting forth the bank’s policy for the protection of its information systems and nonpublic information stored on those information systems. The cybersecurity policy must be based on the Bank’s risk assessment and address at least the following areas of the bank’s operations: La banque doit mettre en œuvre et maintenir une politique écrite approuvée par le conseil d’administration qui expose sa politique de protection de ses systèmes d’information ainsi que des informations non publiques stockées sur ces systèmes d’information. La politique de cybersécurité doit être basée sur l’évaluation des risques de la banque et doit considérer au moins les aspects des opérations de la banque repris ci-après : 119 Official Gazette n° 6bis of 05/02/2018 a) Umutekano w’amakuru; b) Imiyoborere no gushyira mu byiciro amakuru; c) Ibarura ry’umutungo no gucunga ibikoresho; a) Information security ; b) Data governance and classification ; c) Asset inventory and device a) Sécurité de l’information ; b) Gouvernance et classification des données ; d) Kugenzura uburyo bwo kugera ku makuru no d) Access controls and identity d) Contrôles d’accès et gestion de gucunga imyirondoro y’abantu; management ; l’identité ; management ; c) Inventaire des biens et gestion des appareils e) Gukora gahunda y’ikomeza ry’ibikorwa by’ubucuruzi no gusubukura imirimo nyuma y’amage no gutegura ibikenewe muri urwo rwego; Imikorere y’uburyo bukoresha ikoranabuhanga n’ibibazo bijyanye n’uko ubwo buryo buboneka; f) e) Business continuity recovery planning and resources ; and disaster e) Planification et ressources pour la continuité ’d'activité et la reprise après sinistre ; f) Systems operations and availability f) Opérations des systèmes et problèmes concerns ; de disponibilité g) Umutekano w’uburyo bukoresha g) Systems, applications and network g) Sécurité des systèmes et du réseau; ikoranabuhanga n’uw’umuyoboro; security; h) Kugenzura uburyo bukoresha ikoranabuhanga h) Systems, applications and network h) Contrôle des systèmes et du réseau; n’muyoboro; monitoring; i) Gutunganya bukoresha ikoranabuhanga no kunoza imikorere yabwo; uburyo i) Application development, acquisition and quality assurance; i) développement et des d’applications et assurance de qualité ; systèmes j) Umutekano w’ahantu hakorerwa no gukora j) Physical security and environmental j) Sécurité physique et conditionnement amagenzura mu rwego rw’ibidukikije; controls; de l’environnement ; k) Ibanga ry’amakuru yerekeye abakiriya; k) Customer data privacy ; k) La confidentialité des données des l) Imicungire y’ugurisha n’iy’utanga serivisi; l) vendor and third party service provider l) Gestion du vendeur et du tiers management; prestataire de services ; clients ; 120 Official Gazette n° 6bis of 05/02/2018 m) Isuzuma ry’ibyateza ingorane ; no m) Risk management ; and m) Evaluation des risques ; et n) Igisubizo ku bikorwa byo guhungabanya n) Incident management ; n) Réponse aux incidents ; umutekano ; o) Ubukangurambaga ku bakozi ku bijyanye n’umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho ; p) Ibisabwa k’ubunyangamugayo bw’abakozi bakoresha amakuru n’imiyoboro ; q) Ubugenzuzi bw’imiyoboro, bw’ahabikwa amakuru y’umukiliya n’uburyo agerwaho ; o) Awerness of staff with regard to o) Sensibilition du personnel en matière sybersecurity ; de sybersécurité; p) Integrity requirements requirments of staff dealing with data, systems and networks ; p) Exigences relatives aux exigences d'intégrité du personnel traitant les données, les systèmes et les réseaux ; q) Controls to systems, physical locations containing customer information and tools to monitor access by authorized persons. q) Contrôles aux systèmes, emplacements physiques contenant des informations sur les clients et outils pour surveiller l'accès par des personnes autorisées - 7 Verify source ↗
Amasuzuma yo kugerageza kwinjira
AI-assisted research summary: Each bank’s cybersecurity program must include monitoring and testing, including continuous monitoring or periodic penetration testing and vulnerability assessments.
Ingingo ya 7: Amasuzuma yo kugerageza kwinjira no kureba intege nke Article Vulnerability Assessments 7: Penetration Testing and Article 7: Test d’intrusion et évaluations de vulnérabilité Ingingo ya 7: Amasuzuma yo kugerageza kwinjira no kureba intege nke Article Vulnerability Assessments 7: Penetration Testing and Article 7: Test d’intrusion et évaluations de vulnérabilité y’umutekano igomba guteganya Gahunda w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho ibikorwa ya buri banki by’igenzura bigategurwa n’iby’igerageza; hashingiwe ku isuzuma ry’ibyateza ingorane rikozwe na banki, bigashyirwaho hagamijwe gukora isuzuma Ibikorwa ry’ubushobozi by’igenzura n’igerageza bigizwe n’igenzura rihoraho cyangwa kugerageza kwinjira mu buryo bukoresha ikoranabuhanga n’amasuzuma ngarukagihe y’intege nke zabwo. Mu gihe hatariho igenzura rikwiye rihoraho cyangwa hatariho ubundi buryo bwo gahunda. bw’iyo The cybersecurity program for each bank must include monitoring and testing, developed in accordance with the bank’s risk assessment, designed to assess the effectiveness of the bank’s cybersecurity program. The monitoring and testing must include continuous monitoring or periodic penetration testing and vulnerability assessments. Absent continuous monitoring, or other systems to detect, on an ongoing basis, changes in information systems that may create or indicate vulnerabilities, bank’s must conduct: effective Le programme de cybersécurité de chaque banque doit comprendre les mécanismes de contrôle et des tests développés conformément à l’évaluation des risques de la banque et conçus pour évaluer l’efficacité du programme de cybersécurité de la banque. Le contrôle et les tests doivent inclure un contrôle continu ou des tests d’intrusion périodiques ainsi que des évaluations de vulnérabilité. En l’absence d’un contrôle efficace continu ou d’autres systèmes de détection continue des changements au sein des systèmes d’information qui pourraient créer 121 Official Gazette n° 6bis of 05/02/2018 a) Annual penetration testing of the bank’s systems information determined each given year based in on relevant accordance risk assessment; and identified risks with the b) Bi-annual including vulnerability assessments, any systematic scans or reviews of information reasonably systems designed to identify publicly known cybersecurity vulnerabilities in the bank’s information systems based on the risk assessment. les vulnérabilités ou en donner des indications, les banques doivent mener : a) des tests d’intrusion annuels des systèmes d’information de la banque déterminés chaque année en fonction des selon identifiés l’évaluation des risques ; et risques b) Des évaluations de vulnérabilité y compris des semi-annuelles, examens systématiques ou des révisions des systèmes d’information pour conçus raisonnablement identifier les vulnérabilités de cybersécurité connues du public dans les systèmes d’information de la banque sur base de l’évaluation des risques. gutahura ku buryo buhoraho impinduka mu buryo bukoresha ikoranabuhanga zishobora kubutera intege nke cyangwa kuzigaragariza ibimenyetso, amabanki agomba gukora ibi bikurikira: a) Kugerageza kwinjira mu buryo bukoresha ikoranabuhanga bwa banki bikorwa buri mwaka hashingiwe ku ingorane byatahuwe mu byateza isuzuma ingorane ryakozwe; na ry’ibyateza b) Amasuzuma y’ahari byo gutahura biteguwe kugenzura intege nke akorwa kabiri mu mwaka arimo ibikorwa no gusubiramo neza uburyo bukoresha neza ikoranabuhanga hagamijwe ibibazo byerekeranye n’intege nke mu rwego w’ibijyanye rw’umutekano mu n’ikoranabuhanga itangazabumenyi n’itumanaho zigaragara mu buryo bukoresha ikoranabuhanga bukoreshwa na banki zizwi na bose hashingiwe ku isuzuma ry’ibyateza ingorane ryakozwe. - 8 Verify source ↗
Inzira y’ubugenzuzi
AI-assisted research summary: Each bank must securely maintain systems for transaction reconstruction and audit trails, subject to its risk assessment and what is applicable.
Ingingo ya 8: Inzira y’ubugenzuzi Article 8: Audit Trail Article 8: Piste d’audit Ingingo ya 8: Inzira y’ubugenzuzi Article 8: Audit Trail Article 8: Piste d’audit Ishingiye ku isuzuma ry’ibyateza ingorane ryakozwe, buri banki igomba kugira, mu gihe bishoboka, uburyo butekanye: Each bank must securely maintain systems that, to the extent applicable and based on its risk assessment: Chaque banque doit maintenir en toute sécurité des systèmes qui, dans la mesure du possible et sur base de son évaluation des risques: 122 Official Gazette n° 6bis of 05/02/2018 a) bukoze ku rwego bushobora kugarura ibikorwa by’imari kandi bufatika bihagije kugira ngo bushobore gushyigikira ibikorwa n’ishingano zisanzwe za banki; no a) are designed to reconstruct material to and transactions sufficient financial support normal obligations of the bank; and operations b) Gushyiraho inzira z’igenzura zigomba gutahura no gutanga ibisubizo ku bikorwa w’ibijyanye bihungabanya y’umutekano n’ikoranabuhanga mu itangazabumenyi n’itumanaho bishobora guhungabanya igice kimwe gifatika cy’ibikorwa bisanzwe bya banki. b) include audit trails designed to detect and respond to cybersecurity incidents that have reasonable likelihood of materially harming any material part of the normal operations of the bank. a) sont conçus de façon à reconstruire les transactions importantes financières suffisant pour supporter les opérations et obligations normales de la banque ; et b) incluent des pistes d’audit conçus pour détecter et répondre aux incidents de cybersécurité qui vraisemblablement peuvent porter atteinte sérieuse à une partie considérable des activités normales de la banque. - 9 Verify source ↗
Gucunga umutekano w’imirongo
AI-assisted research summary: Banks must use KYC, sensitive-data protection, mobile security, user training, identity-system integration, and access controls for alternative delivery channels.
Ingingo ya 9: Gucunga umutekano w’imirongo itwara amakuru isimbura iyindi Article 9: Alternative Delivery Channels (ADC) Security Management Article 9: Gestion de la sécurité des canaux de distribution alternatifs Ingingo ya 9: Gucunga umutekano w’imirongo itwara amakuru isimbura iyindi Article 9: Alternative Delivery Channels (ADC) Security Management Article 9: Gestion de la sécurité des canaux de distribution alternatifs (9.1) Banki igomba kwita ku nzira zikurikizwa mu kumenya umwirondoro w’umukiriya uko bikwiye (KYC)igihe yandika umukiriya muri serivisi z’imari zitangwa hakoreshejwe interineti cyangwa uburyo bwimuka, ikarinda uko bikwiye amakuru akwiye kwitonderwa cyane, ikarinda umutekano w’ibyimukanwa igaha amahugurwa uko bikwiye kandi abakoresha uburyo bw’ikoranabuhanga. (9.1) The bank must ensure adequate Know Your Customer (KYC) procedures during customer registration for online and Mobile Financial Services, adequate sensitive data protection, adequate mobile security protection and user training. adéquates (9.1) La banque doit veiller à ce qu’il y ait des procédures de « Connaissance de son Client (KYC) » lors de l’inscription des clients pour les services financiers en ligne ou mobiles, une protection appropriée des données sensibles, une protection appropriée de la sécurité mobile et la formation des utilisateurs. (9.2) Ikoranabuhanga rya banki rigomba guhuzwe kugirango r’iry’urwego abeho uburyo bwo gutahura umukiriya. ry’irangamuntu (9.2) the core banking systems must be intergeted with National Identification system identity for verification mechanism. the customer (9.2) les systèmes bancaires de base doivent être intervertis avec le système national d'identification pour le mécanisme de vérification de l'identité du client. 123 (9.3) Banki igomba gukoresha uburyo bw’umutekano butuma umuntu uwo ari we wese atemererwa kugera ku makuru akwiye kwitonderwa cyane yaba abitswe cyangwa ari mu nzira ahererekanywa nk’uko biteganywa n’aya mabwiriza. Official Gazette n° 6bis of 05/02/2018 (9.3) The bank shall employ security mechanisms that prevent unauthorized access to sensitive data at rest or in transit as contained in this regulation. (9.3) La doit banque employer des mécanismes de sécurité qui préviennent un accès non autorisé aux données sensibles en repos ou en transit tels que prévus dans le présent règlement. - 10 Verify source ↗
Isuzuma ry’ibibazo bishobora
AI-assisted research summary: Each bank must periodically assess information-system risk and document the assessment under written procedures.
Ingingo ya 10 : Isuzuma ry’ibibazo bishobora kuvuka Article 10 : Risk Management Article 10 : Evaluation des risques Ingingo ya 10 : Isuzuma ry’ibibazo bishobora kuvuka Article 10 : Risk Management Article 10 : Evaluation des risques (10.1) Buri banki igomba gukora isuzuma ngarukagihe rihagije ry’ibyateza ingorane mu rwego rw’uburyo bukoresha ikoranabuhanga kugira ngo habashe gutunganywa gahunda y’umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho nk’uko biteganywa n’aya mabwiriza. Bene iryo suzuma rigomba kugenda rihuzwa n’igihe uko bishoboka kose mu rwego rwo gukemura ibibazo bijyanye buryo zibonetse n’impinduka bukoreshwa bukoresha na ikoranabuhanga, mu makuru atari rusange kimwe no mu bikorwa by’ubucuruzi byayo. ry’ibyateza ingorane banki mu 10.1) Each bank shall conduct a periodic risk assessment of the bank’s information systems sufficient to inform the design of the cybersecurity program as required by this regulation. Such risk assessment reasonably shall be updated necessary to address changes to the bank’s information systems, non public information or business operations. as (10.1) Chaque banque doit mener une des risques du programme évaluation périodique auxquels ses systèmes d’information font face suffisante pour informer la conception de cybersécurité tel que requis par le présent règlement. Cette évaluation des risques doit être mise à jour aussi raisonnablement que nécessaire en vue de répondre aux changements des systèmes d’information de la banque, des informations non publiques ou des opérations commerciales. (10.2) Isuzuma ry’ibyateza ingorane banki rigomba guteganya ivugururwa ry’amagenzura kugira ngo uburyo bukoreshwa bubashe kujyana n’iterambere ry’ikoranabuhanga kimwe no gukemura ibibazo biba byugarije uburyo bukoresha ikoranabuhanga kandi rigomba kwita ku byateza ingorane byihariye mu bikorwa bya banki bifite aho bihuriye 10.2) The bank’s risk assessment must allow for revision of controls to respond to and technological evolving threats and shall consider the particular risks of the bank’s business operations related to cybersecurity, non public information collected or stored, information systems utilized and the developments (10.2) L’évaluation des risques de la banque doit prévoir des possibilités de révision des contrôles en vue de répondre aux développements technologiques et aux menaces évolutives et doit considérer les risques particuliers des opérations commerciales de la banque relatifs à la cybersécurité, aux informations non 124 y’umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho, amakuru atari rusange yakusanyijwe cyangwa abitswe, ikoranabuhanga uburyo bukoreshwa cyangwa no kuba uburyo bwo kugenzura buboneka kandi bukora neza mu rwego rwo kurinda amakuru atari rusange cyangwa uburyo bukoresha ikoranabuhanga. bukoresha (10.3) Isuzuma ingorane ry’ibyateza rikorwa hakurikijwe politiki n’inzira zikurikizwa zanditswe kandi ibirivuyemo bikandikwa. Izo politiki n’izo nzira zikurikizwa ziba zikubiyemo: a) byiciro ibigenderwaho mu gusuzuma no gushyira mu ibyateza ingorane mu rwego rw’umutekano w’ibijyanye n’ikoranabuhanga mu n’itumanaho itangazabumenyi byabonetse ibibazo byugarije banki muri urwo rwego; cyangwa b) ibigenderwaho mu gusuzuma ibanga, ubudakemwa, umutekano n’iboneka ry’uburyo bukoresha ikoranabuhanga bukoreshwa kimwe n’amakuru atari rusange harimo no kuba uburyo bwo kugenzura bukwiye hakurikijwe ingorane byagaragaye; no ibyateza banki na Official Gazette n° 6bis of 05/02/2018 availability and effectiveness of controls to protect nonpublic information and information systems. 10.3) The risk assessment must be carried out in accordance with written policies and procedures and shall be documented. Such policies and procedures shall include: publiques collectées ou stockées, aux systèmes d’information utilisés et à la disponibilité et l’efficacité des contrôles en vue de la protection des informations non publiques systèmes d’information. et des (10.3) L’évaluation des risques doit être menée et conformément être procédures documentée. De telles politiques et procédures doivent comprendre: politiques doit et aux écrites a) Criteria for the evaluation and categorization of identified cybersecurity risks or threats facing the bank; a) les critères d’évaluation et de catégorisation des risques de cybersécurité identifiés ou de menaces auxquelles la banque est confrontée; b) Criteria for the assessment of integrity, the confidentiality, security and availability of the bank’s/FI information systems and nonpublic information, the adequacy of including existing controls in the context of identified risks; and 125 b) les critères d’évaluation de la confidentialité, de l’intégrité, de la sécurité et de la disponibilité des systèmes d’information de la banque et des informations comprenant non l’adéquation contrôles existants dans le contexte des risques identifiés ; et publiques des Official Gazette n° 6bis of 05/02/2018 c) bigaragaza ibyateza uburyo ibisabwa ingorane ubukana bw’ byagaragaye bushobora kugabanywa cyangwa kwakirwa hashingiwe ku isuzuma ry’ ibyateza ingorane n’uburyo ryakozwe gahunda y’umutekano w’ibijyanye mu n’ikoranabuhanga itangazabumenyi n’itumanaho izabasha gukemura izo ngorane. c) Acceptance criteria describing how identified risks will be treated or accepted based on the risk assessment and how the cybersecurity program will address the risks. c) les exigences qui décrivent comment les risques identifiés seront mitigés ou acceptés compte tenu de l’évaluation des risques et la façon dont le programme de cybersécurité traitera ces risques. - 11 Verify source ↗
Undi muntu utanga serivisi
AI-assisted research summary: A bank must have written policies and procedures to protect systems and nonpublic information handled by third-party service providers.
Ingingo ya 11: Undi muntu utanga serivisi Article 11: Third Party Service Provider Article 11: Tiers prestataire de services Ingingo hakoreshejwe ibintu byinshi ya 12: Gusuzuma umwirondoro Ingingo ya 11: Undi muntu utanga serivisi Article 11: Third Party Service Provider Article 11: Tiers prestataire de services umutekano (11.1) Banki igomba gushyira mu bikorwa politiki n’inzira zikurikizwa zanditswe hagamijwe w’uburyo kubungabunga bukoresha ikoranabuhanga n’amakuru atari rusange ashobora kugerwaho cyangwa abitswe n’abandi batanga serivisi. Izo politiki n’izo nzira zikurikizwa zigomba gushingira ku isuzuma ry’ibyateza ingorane ryakozwe na banki kandi, aho bishoboka hose, zigomba kugira icyo ziteganya kuri ibi bikurikira: a) Itahurwa n’isuzuma ry’ibyateza ingorane byerekeranye n’abandi bantu batanga serivisi; (11.1) The bank must the security of implement written policies and procedures designed to information ensure systems and nonpublic information that are accessible to, or held by, third party service providers. Such policies and procedures shall be based on the risk assessment of the bank and shall address to the extent applicable: a) the identification risk assessment of third party service providers; and b) Imigenzereze y’ibanza ishoboka yo mu w’ibijyanye rwego n’ikoranabuhanga mu itangazabumenyi rw’umutekano b) minimum cybersecurity practices required to be met by such third 126 (11.1) et La banque doit mettre en exécution des politiques et des procédures écrites conçues pour assurer la sécurité des systèmes des d’information informations non publiques qui sont accessibles aux tiers prestataires de services ou détenues par eux. De telles politiques et procédures doivent être basées sur l’évaluation des risques de la banque et doivent porter, dans la mesure du possible, sur : a) l’identification et l’évaluation des risques des tiers prestataires de services ; b) le minimum de pratiques de cybersécurité exigées aux tiers prestataires de service pour faire des affaires avec la banque; Official Gazette n° 6bis of 05/02/2018 party service providers in order for them to do business with the bank; c) due diligence processes used to evaluate of cybersecurity practices of such third party service providers; and adequacy the c) les de processus diligence raisonnable utilisés pour évaluer pratiques de l’efficacité cybersécurité tiers ces prestataires de service ; et des de d) periodic assessment of such third party service providers based on the risk they present and the continued their cybersecurity adequacy of practices. d) l’évaluation périodique de ces tiers prestataires de services sur base des et risques qu’ils leurs l’efficacité continue de pratiques de cybersécurité. présentent n’itumanaho isabwa kuba yujujwe n’abandi bantu batanga serivisi kugira ngo babashe gukorana na banki muri urwo rwego; c) Inzira zo kugenzura mu bushishozi gusuzuma zikoreshwa mu niba imigenzereze y’abo bantu bandi batanga serivisi mu rw’umutekano rwego w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho ikwiye; d) Gukorera isuzuma ngarukagihe abo bandi batanga serivisi hashingiwe ku ngorane bigaragara ko bashobora guteza no ku kuba imigenzereze yabo mu rwego rw’umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho ihora ikwiye. (11.2) Izo politiki n’inzira zikurikizwa zigomba kuba zikubiyemo imirongo ngenderwaho yo kumenya imyifatire ndetse no kurinda amasezerano yerekeranye n’abandi batanga serivisi harimo uko bishoboka kose imirongo ngenderwaho mu gusuzuma: (11.2) Such policies and procedures must include relevant guidelines for due diligence and/or contractual protections relating to third party service providers including the extent applicable guidelines addressing: to (11.2) De comprendre telles politiques et procédures doivent les principes directeurs appropriés d’identification et/ou les protections contractuelles en rapport avec les tiers prestataires de services y compris, dans la mesure du possible, des principes directeurs qui traitent : a) politiki n’inzira zikurikizwa n’undi muntu utanga serivisi mu kugenzura uburyo bwo kugera ku makuru harimo imikoreshereze y’uburyo bwo gusuzuma umwirondoro a) the third party service provider’s policies and procedures for access controls, including its use of multi- factor authentication as required by a) les politiques et les procédures de contrôles d’accès du tiers prestataire de services y compris son utilisation d’authentification multi- factorielle 127 Official Gazette n° 6bis of 05/02/2018 hagendewe ku bintu byinshi nk’uko biteganywa mu ngingo ya 12 y’aya mabwiriza, kugabanya hagamije abashobora kugera ku buryo bukoresha ikoranabuhanga bukoreshwa kimwe no ku makuru atari rusange; - 12 Verify source ↗
Multi-Factor Authentication
AI-assisted research summary: Banks must use risk-based controls to protect non-public information and systems, and must require multi-factor authentication for people accessing internal networks from outside unless an ISU head approves an equally or more secure alternative in writing.
Article 12: Multi-Factor Authentication Article 12: Authentification multi-factorielle Article 12 of this Regulation, to limit access to relevant Information systems non-public information; and conformément à l’article 12 du présent Règlement en vue de limiter l’accès aux systèmes d’information et informations non publiques aux concernés ; b) politiki n’inzira zikurikizwa n’undi muntu utanga serivisi mu gukoresha uburyo bw’ibanga nk’uko bisabwa mu ngingo ya 12 y’aya mabwiriza hagamijwe kurinda amakuru atari rusange ari mu nzira ahererekanywa cyangwa abitswe; b) the third party service provider’s policies and procedures for use of encryption as required by Article 12 of this Regulation to protect non- public information in transit and at rest; c) d) Imenyesha rigomba gukorerwa banki mu gihe habayeho ikibazo cy’umutekano n’ikoranabuhanga mu w’ibijyanye itangazabumenyi gifite ingaruka zitaziguye ku buryo bukoresha ikoranabuhanga bwa banki cyangwa ku makuru yayo atari rusange abitswe n’undi muntu utanga serivisi; na n’itumanaho amamenyekanisha n’ ubwiyemeze bitangwa kuri politiki n’inzira zikurikizwa n’undi muntu utanga serivisi mu rwego w’ibijyanye rw’umutekano n’ikoranabuhanga mu itangazabumenyi byerekeranye n’itumanaho n’umutekano bukoresha ikoranabuhanga bukoreshwa na banki cyangwa uw’amakuru yayo atari rusange. ku w’uburyo c) notice to be provided to the bank in the event of a cybersecurity incident directly impacting the bank’s/FI information systems or the bank’s non-public information being held by the third party service provider; and d) representations and warranties addressing the third party service provider’s cybersecurity policies and procedures that relate to the security bank’s/FI information systems or non-public information. the of 128 b) les politiques et les procédures du tiers prestataire de services pour l’utilisation chiffrement du conformément à l’Article 12 du présent Règlement en vue de protéger des informations non publiques en transit ou en repos ; c) une notification à donner à la banque en cas d’incident de cybersécurité qui a un impact direct sur les systèmes d’information de la banque ou sur des informations non publiques de la banque détenues par tiers prestataire de services ; et le d) les déclarations et les politiques et garanties concernant les procédures de cybersécurité du tiers prestataire de services ayant trait à la sécurité des systèmes d’information ou aux informations non publiques de la banque. Ingingo hakoreshejwe ibintu byinshi ya 12: Gusuzuma umwirondoro Official Gazette n° 6bis of 05/02/2018 Article 12: Multi-Factor Authentication Article 12: Authentification multi-factorielle ashobora (12.1) Ishingiye ku isuzuma ry’ibyayiteza ingorane igomba gukoresha yakoze, buri banki kuba akwiye amagenzura umwirondoro akubiyemo gusuzuma ibintu byinshi w’abantu hakoreshejwe bibaranga cyangwa gusuzuma umwirondoro w’abantu hashingiwe ku byateza ingorane hagamijwe kubakumira kugera ku makuru atari rusange cyangwa k’uburyo bukoresha ikoranabuhanga banki ikoresha. (12.2) Gusuzuma umwirondoro w’umuntu hakoreshejwe ibintu byinshi bimuranga bigomba gukorwa ku muntu uwo ari we wese winjira mu miyoboro ya banki y’imbere anyuze mu miyoboro yo hanze cyeretse gusa iyo ukuriye ISU yemeye mu nyandiko ikoreshwa ry’ubundi buryo bumeze nk’ubwo cyangwa ubundi buryo bw’igenzura bufite umutekano kurusha ubwongubwo. (12.1) Based on its risk assessment, each bank shall use effective controls, which may include multi-factor authentication or risk-based authentication, to protect to against nonpublic information or information systems. unauthorized access (12.2) internal networks Multi-factor authentication shall be utilized for any individual accessing the from an bank’s external network, unless the bank’s head of ISU has approved in writing the use of reasonably equivalent or more secure access controls. qui efficaces (12.1) Sur base de son évaluation des risques, chaque banque doit utiliser des outils de contrôle peuvent comprendre une authentification multi – factorielle ou une authentification basée sur des risques en vue de se protéger aux contre informations ou systèmes d’information. autorisé publiques l’accès non non (12.2) L’authentification multifactorielle doit être utilisée pour toute personne qui accède aux réseaux internes de la banque à partir d’un réseau externe, à moins que le chargé de ISU de la banque n’ait approuvé par écrit l’utilisation des d’accès outils raisonnablement équivalents ou plus sécurisés. contrôle de - 13 Verify source ↗
Igabanywa ry’amakuru agomba
AI-assisted research summary: Each bank must have a data retention policy for keeping and periodically disposing of nonpublic information, unless the information must be retained by law or regulation.
Ingingo ya 13: Igabanywa ry’amakuru agomba kubikwa Article 13: Limitations on Data Retention Article 13: Limitations sur la rétention des données Ingingo ya 13: Igabanywa ry’amakuru agomba kubikwa Article 13: Limitations on Data Retention Article 13: Limitations sur la rétention des données Mu rwego rwa gahunda y’umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho, buri banki igomba gushyiraho politiki n’inzira zikurikizwa mu gushyingura mu buryo bwizewe kandi mu buryo buhoraho amakuru yose atari rusange, cyeretse gusa iyo ayo makuru agomba As part of its cybersecurity program, each bank must have a data retention policy for the secure keeping and disposal on a periodic basis of any nonpublic information identified as per their Risk assessment, except where such information is otherwise required to be retained by law or regulation. 129 le cadre de Dans son programme de cybersécurité, chaque banque doit inclure des politiques et des procédures de disposition sécurisée, de toute information non publique, sauf là où ces informations doivent être conservées en vertu de la loi ou d’un règlement. façon périodique, de Official Gazette n° 6bis of 05/02/2018 kubikwa hakurikijwe ibisabwa n’itegeko cyangwa amabwiriza. - 14 Verify source ↗
Amahugurwa n’igenzurwa
AI-assisted research summary: Each bank must maintain cybersecurity awareness controls and train its personnel regularly.
Ingingo ya 14: Amahugurwa n’igenzurwa ry’ukoresha uburyo bukoresha ikoranabuhanga Article 14: User Training and Monitoring Article 14: Formation et contrôle de l’utilisateur Ingingo ya 14: Amahugurwa n’igenzurwa ry’ukoresha uburyo bukoresha ikoranabuhanga Article 14: User Training and Monitoring Article 14: Formation et contrôle de l’utilisateur (14.1) Mu rwego rwa gahunda yayo y’umutekano mu w’ibijyanye itangazabumenyi n’itumanaho, buri banki igomba: n’ikoranabuhanga (14.1) As part of its cybersecurity program, each bank must: (14.1) Dans le cadre de son programme de cybersécurité, chaque banque doit : a) gushyira mu politiki, bikorwa inzira ashingiye ku zikurikizwa n’amagenzura byateza ingorane hagamijwe kugenzura ibikorwa by’abakoresha uburyo bukoresha ikoranabuhanga babyemerewe no gutahura abagera cyangwa abakoresha ubu buryo batabyemerewe ; b) Guha buri gihe abakozi bose amahugurwa ajyanye n’igihe agaragaza ibyateza ingorane byagaragajwe mu ry’ibyateza kugira ngo ingoraneryakozwe na banki ikwiye ku imyumvire babashe kugira umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho ; isuzuma a) design a consistent and updated security awareness program line with institution’s risk assessment, strategy and current cybersecurity threats and trends ; in a) mettre en œuvre des politiques, des procédures et des contrôles basés sur des risques conçus pour contrôler les activités des utilisateurs autorisés et pour détecter l’accès ou l’utilisation non autorisés ; b) provide regular cybersecurity awareness training for all personnel that interacts with institution’s information system including but not limited to staff, interns, third party ; b) donner à tout le personnel une formation régulière de prise de conscience sur la cybersécurité qui est à jour pour refléter les risques identifiés par la banque dans son évaluation des risques ; c) Kugenzura akamaro k’amahugurwa biciye mu c) evaluate the effectiveness of bibazo n’igeerageza ; awareness quizes and test simulations. training through 130 the regular c) évaluer l'efficacité de la sensibilisation au moyen de tests réguliers et de test de simulations. Official Gazette n° 6bis of 05/02/2018 - 15 Verify source ↗
Kurinda amakuru atari rusange
AI-assisted research summary: Banks must use encryption and other controls to protect non-public information, with limited alternatives allowed if encryption is not feasible.
Ingingo ya 15: Kurinda amakuru atari rusange Article 15: Encryption of Non-public Information Article 15: Cryptage des informations non publiques 102 Official Gazette n° 6bis of 05/02/2018 Ingingo ya 15: Kurinda amakuru atari rusange Article 15: Encryption of Non-public Information Article 15: Cryptage des informations non publiques (15.1) Nka kimwe mu bigize gahunda yayo y’umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho kandi ishingiye ku isuzuma ry’ ibyateza ingorane, buri banki igomba gushyira mu bikorwa uburyo bwo kugenzura burimo gusobeka hagamijwe kurinda amakuru atari rusange abitswe cyangwa yoherejwe na banki yaba ari mu nzira mu miyoboro yo hanze cyangwa abitswe. implement controls, (15.1) As part of its cybersecurity program, based on its risk assessment, each bank including shall encryption, nonpublic information held or transmitted by the bank both in transit over external networks and at rest. protect to (15.1) Dans le cadre de son programme de cybersécurité et sur base de son évaluation des risques, chaque banque doit mettre en œuvre des contrôles, y compris le cryptage, pour protéger des informations non publiques gardées ou transmises par la banque qu’elles soient en transit sur des réseaux externes ou au repos. (15.2) Mu gihe cyose banki isanze bidashoboka gusobeka makuru atari rusange ari mu nzira mu miyoboro yo hanze, ishobora kurinda bene ayo makuru yifashishije amagenzura asimbura neza yasubiwemo kandi yemewe n’ukuriye ISU wa banki. buryo ubwo akora (15.2) To the extent a bank determines that encryption of nonpublic information in transit over external networks is infeasible, the bank may instead secure information using such nonpublic compensating effective controls reviewed and approved by the bank’s head of ISU. alternative (15.2) Dans la mesure où la banque estime que informations non le cryptage des publiques en transit sur des réseaux externes n’est pas faisable, celle ci peut par telles sécuriser informations non publiques en utilisant des contrôles compensatoires efficaces examinés et approuvés par le chargé de ISU de la banque. contre de (15.3) Mu gihe cyose banki isanze bidashoboka gusobeka amakuru atari rusange abitswe, ishobora ayo makuru yifashishije amagenzura asimbura ubwo buryo akora neza yasubiwemo kandi yemewe n’ukuriye ISU wa banki. kurinda bene (15.3) To the extent a bank determines that encryption of Nonpublic Information at rest is infeasible, the bank may instead secure such Nonpublic Information using effective alternative compensating controls reviewed and approved by the bank’s head of ISU. (15.3) Dans la mesure où la banque estime que le cryptage des informations non publiques en repos n’est pas faisable, celle ci peut par contre sécuriser de telles informations non publiques en utilisant des contrôles compensatoires efficaces examinés et approuvés par le chargé de ISU la banque. 131 uburyo bw’ibanga (15.4) Mu gihe cyose banki ikoresha amagenzura asimbura nk’uko byavuzwe haruguru, ISU agomba kongera rikoresha gusuzuma niba isobeka n’imikorere y’amagenzura arisimbura nibura buri mwaka . irindamakuru rishoboka Official Gazette n° 6bis of 05/02/2018 (15.4) To the extent that a bank is utilizing compensating controls as mentioned above, the feasibility of encryption and the compensating effectiveness of controls shall be reviewed by ISU at least annually. des d’utiliser (15.4) Dans la mesure où une banque est en train contrôles compensatoires tels que mentionnés ci- haut, le ISU doit passer en revue au moins une fois par an la faisabilité du cryptage et l’efficacité des contrôles compensatoires. - 16 Verify source ↗
Gahunda yo gukemura ibibazo
AI-assisted research summary: Each bank must have a written incident response and business continuity plan for cybersecurity incidents.
Ingingo ya 16 Gahunda yo gukemura ibibazo bivutse Article 16 Incident Response and business continuity management Article 16 Plan d’intervention en cas d’incident Ingingo ya 16 Gahunda yo gukemura ibibazo bivutse Article 16 Incident Response and business continuity management Article 16 Plan d’intervention en cas d’incident n’ikoranabuhanga (16.1) Mu rwego rwa gahunda yayo y’umutekano w’ibijyanye mu itangazabumenyi n’itumanaho, buri banki igomba gushyiraho gahunda yo gukemura ibibazo bivutse yanditse igamije gukemura ibyo bibazo ako kanya no kuyikura mu kibazo icyo aricyo cyose cyerekeranye n’umutekano w’ibijyanye n’ikoranabuhanga n’itumanaho mu kibangamira ibanga , ubudakemwa cyangwa ukuboneka bukoresha k’uburyo ikoranabuhanga bukoreshwa na banki cyangwa imikorere ihoraho y’ubwoko ubwo ari bwo bwose bw’ubucuruzi cyangwa bw’ibikorwa bya banki. itangazabumenyi and response (16.1) As part of its cybersecurity program, each bank shall establish a written incident business continuity management plan designed to promptly respond to, and recover from, any cybersecurity incident materially affecting the confidentiality, integrity or availability of the bank’s information systems or the continuing functionality of any aspect of the bank’s business or operations. (16.1) Dans le cadre de son programme de cybersécurité, chaque banque doit élaborer un plan écrit d’intervention en cas d’incident conçu pour réagir et sortir de d’un ponctuellement cybersécurité qui affecte matériellement la la confidentialité, systèmes disponibilité la d’information de fonctionnalité continue d’un aspect quelconque de ses activités ou de ses opérations. des la banque ou l’intégrité ou incident (16.2) Iyo gahunda yo gukemura ibibazo bivutse igomba kwita kuri ibi bintu bikurikira: (16.2) Such incident response and business continuity management plan shall address the following areas: (16.2) Ce plan d’intervention en cas d’incident doit porter sur les aspects repris ci- après: 132 Official Gazette n° 6bis of 05/02/2018 a) Inzira zikurikizwa muri banki imbere zo gukemura ikibazo cyerekeranye n’igikorwa gihungabanya umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho ; a) the internal responding incident and disasters; to processes for cybersecurity a) les processus internes de réponse à un incident de cybersécurité; b) Intego za gahunda yo gukemura ibibazo bivutse; b) the goals of the incident response and business continuity plans; b) les objectifs du plan d’intervention en cas d’incidents; c) Gusobanura mu buryo bwumvikana uruhare, n’inzego inshingano z’ubuyobozi zifatirwamo ibyemezo; d) Itumanaho no guhanana amakuru imbere muri banki no hanze yayo ; e) Kumenya ibikenewe mu rwego rwo kongera ingufu ahagaragaye intege nke mu buryo bwo guhanahana amakuru bukoreshwa n’ubugenzuzi bijyana; f) Gukora inyandiko na raporo ku bikorwa bihungabanya umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho no ku bikorwa byerekeranye no gukemura ibibazo byavutse; no g) Gusuzuma no gusubiramo gahunda yo gukemura ibibazo bivutse uko hakurukijwe bibaye ngombwa c) the definition of clear responsibilities decision-making authority; and roles, levels of d) external internal and communications and information sharing; e) identification of requirements for the remediation of any identified weaknesses in information systems and associated controls; f) documentation and reporting regarding cybersecurity events and related incident response activities; and c) la définition claire responsabilités d’autorité de prise de décision; des rôles, niveaux et d) communications échange d’information externes et internes; et e) Identification des besoins pour remédier à toutes les faiblesses systèmes identifiées dans d’information les que contrôles associés ; ainsi les f) la documentation et production de rapports concernant les événements de cybersécurité ainsi que les activités connexes d’intervention en cas d’incident ; et g) the evaluation and revision as necessary of the incident response g) l’évaluation et la révision au tant que nécessaire du plan d’intervention 133 Official Gazette n° 6bis of 05/02/2018 igikorwa gihungabanya y’umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho cyabaye. and business continuity following a cybersecurity event. plans en cas d’incident à la suite d’un événement de cybersécurité. - 17 Verify source ↗
Imenyesha rikorerwa Banki Nkuru
AI-assisted research summary: Banks must notify the Central Bank quickly after a cybersecurity incident and send a full incident report within 24 hours.
Ingingo ya 17 Imenyesha rikorerwa Banki Nkuru Article 17 Notices to the Central Bank Article 17 Notifications à la Banque Centrale Ingingo ya 17 Imenyesha rikorerwa Banki Nkuru Article 17 Notices to the Central Bank Article 17 Notifications à la Banque Centrale (17.1) Banki igomba kumenyesha Banki Nkuru ako kanya uko bishoboka mu gihe kitarenze amasaha abiri (2) uhereye igihe icyo gikorwa cyibereyeho cyangwa igihe hamenyekanye gihungabanya igikorwa ko umutekano w’ibijyanye n’ikoranabuhanga mu itangazabumenyi n’itumanaho gishobora kuba kiri muri bumwe muri ubu bwoko bukurikira: habayeho (17.1) (17.1) The bank must notify Central Bank as promptly as possible within a period not exceeding two (2) hours from the occurrence of the incident or from a that a cybersecurity determination incident has occurred that is either of the following: La banque doit notifier à la Banque Centrale aussi rapidement que possible endéans une période ne dépassant pas deux (2) heures à compter de la survenance de l’incident ou de la constatation qu’il s’est produit un incident de cybersécurité qui peut revêtir l’un des aspects suivants : a) Igikorwa gihungabanya umutekano w’ibijyanye n’ikoranabuhanga mu n’itumanaho itangazabumenyi gishobora kubuza ishami runaka rya banki gukomeza ibikorwa byaryo bisanzwe byo guha serivisi z’imari abakiriya baryo, cyangwa b) Ibikorwa bihungabanya w’ibijyanye y’umutekano mu n’ikoranabuhanga itangazabumenyi n’itumanaho uko bigaragara bishobora guhungabanya kuburyo bugaragara igice gifatika cy’ibikorwa bisanzwe bya banki. a) cybersecurity incident that may prevent a specific bank branch from continuing its normal operations for customer-facing transactions, and a) un incident de cybersécurité qui peut empêcher une succursale bancaire donnée de continuer ses activités normales dans le cadre des opérations avec les clients, et b) cybersecurity events that have a reasonable likelihood of materially harming any material part of the normal operation(s) of the bank. b) des événements de cybersécurité qui peuvent vraisemblablement porter sérieuse à une partie atteinte importante des activités normales de la banque. 134 Official Gazette n° 6bis of 05/02/2018 (17.2) Banki igomba gushyikiriza Banki Nkuru raporo yuzuye y’igikorwa gihungabanya umutekano mu gihe cy’amasaha 24 kuva igikorwa kibaye. (17.2) The Bank must submit to the Central Bank the full incident report within 24 hours from the incident. the occurrence of (17.2) La Banque doit soumettre à la Banque Centrale le rapport d'incident complet dans les 24 heures suivant la survenance de l'incident. (17.3) Banki igomba gushyikiriza Banki Nkuru inyandiko nk’uko igaragara ku mugereka yemeza ko gahunda ya banki y’umutekano w’ibijyanye mu itangazabumenyi n’itumanaho yubahiriza ibyo isabwa n’aya mabwiriza. Iyo nyandiko igomba gushyikirizwa Banki Nkuru mu gihe kitarenze itariki ya 15 Mutarama buri mawaka. n’ikoranabuhanga (17.3) The bank shall submit to the Central Bank on annual basis a written statement as per the appendix certifying that the bank cyber securtiy program is in compliance with the requirements set forth in this Regulation. The statement shall be submitted not later than 15th January of each year. (17.3) La banque doit transmettre annuellent à la Banque Central une déclaration écrite le programme de certifiant que cybersecurité se conforme aux exigences du présent Règlement. Cette declaration doit etre tramsmit au plus tard le 15 janvier de chaque année - 18 Verify source ↗
Ibyerekeranye n’ibanga
AI-assisted research summary: Bank information given under this Regulation may be exempt from disclosure.
Ingingo ya 18 Ibyerekeranye n’ibanga UMUTWE WA III: INGINGO ZINYURANYE N’IZISOZA Article 18 Confidentiality CHAPTER III: MISCELLANEOUS AND FINAL PROVISIONS Article 18 Confidentialité CHAPITRE DIVERSES ET FINALES III: DISPOSITIONS Ingingo ya 18 Ibyerekeranye n’ibanga Article 18 Confidentiality Article 18 Confidentialité Amakuru atangwa na banki hakurikijwe aya mabwiriza ntarebwa n’ingingo z’itangaza ry’amakuru y’imirimo z’Itegeko y’amabanki cyangwa irindi tegeko bijyanye. imitunganyirize rigena Information provided by a bank pursuant to this Regulation is subject to exemptions from disclosure under the Banking Law or any other applicable law. Les informations fournies par une banque conformément au présent Règlement sont sujettes à des dispenses de divulgation conformément à la Loi portant organisation de l’activité bancaire ou à toute autre loi applicable. UMUTWE WA III: INGINGO ZINYURANYE N’IZISOZA CHAPTER III: MISCELLANEOUS AND FINAL PROVISIONS CHAPITRE DIVERSES ET FINALES III: DISPOSITIONS - 19 Verify source ↗
Ibihano n’ibyemezo byo mu rwego
AI-assisted research summary: If a bank does not meet the Regulation’s requirements, the Central Bank may apply sanctions allowed by the relevant law or related regulation.
Ingingo ya 19 Ibihano n’ibyemezo byo mu rwego rw’ubutegetsi Article 19 Penalties and administrative sanctions Article administratives 19 Pénalités et sanctions Ingingo ya 19 Ibihano n’ibyemezo byo mu rwego rw’ubutegetsi Article 19 Penalties and administrative sanctions Article administratives 19 Pénalités et sanctions Iyo banki itabashije kubahiriza ibisabwa muri aya mabwiriza, Banki Nkuru ishobora kuyifatira ibihano imitunganyirize biteganywa n’Itegeko rigena Where the bank fails to satisfy any of the requirements of this Regulation, the Central Bank may apply any sanctions available under relevant provisions of the Law concerning Lorsqu’ une banque ne parvient pas à répondre aux exigences du présent Règlement, la Banque Centrale peut appliquer toute sanction prévue par les dispositions applicables de la Loi portant 135 Official Gazette n° 6bis of 05/02/2018 y’imirimo y’amabanki z’amabwiriza akurikizwa. cyangwa mu ngingo organization of banking and/or provisions of a relevant regulation. organisation de l’activité bancaire et/ou les dispositions d’un règlement applicable. - 20 Verify source ↗
Igihe ntarengwa cyo kubahiriza
AI-assisted research summary: Banks must meet two compliance deadlines: 18 months for article 3 and 6 months for articles 4, 5, and 6.
Ingingo ya 20 : Igihe ntarengwa cyo kubahiriza aya mabwiriza Article 20 : Deadline for conforming to the provisions of this regulation Article 20 dispositions du présent règlement : Délai de conformité aux Ingingo ya 20 : Igihe ntarengwa cyo kubahiriza zimwe mu ngingo z’ aya mabwiriza Article 20 : Deadline for conforming to certain provisions of this regulation Article 20 : Délai de conformité aux certain dispositions du présent règlement igihe kitarenze amezi Amabanki ahawe icumi n’umunane (18) uhereye igihe iri tegeko ritangarijwe mu Igazeti ya Leta ya Repubulika y’u Rwanda kugira ngo abe yahuje imikorere yayo n’ibiteganywa mu ngingo ya 3 y’aya mabwiriza. Amabanki ahawe igihe cy’amazi atandatu (6) kugirango zubahiruze ibikubiye muri ngo ya 4, iya 4 n’iya 6 y’aya mabwiriza, uhereye igihe uhereye igihe atangarijwe mu Igazeti ya Repubulika y’u Rwanda Banks shall have eighteen (18) months as from the entry into force of this regulation to conform their functioning with the provisions of article 3 of this regulation. Les banques disposent d'un delai de dix huit (18) mois pour se conformer aux exigences de l'article 3 de present règlement, suivant la date la date d’entrée en vigueur du présent reglement. Banks are given a maximun of six (6) months to comply with provisions of Article 4, 5 and 6 of this regulation, starting from the date of its publication in the Official Gazette of the Republic of Rwanda. Les banques disposent d'un maximum de six (6) mois pour se conformer aux dispositions des - 21 Verify source ↗
Ivanwaho ry’ingingo z’amabwiriza
AI-assisted research summary: Previous provisions that conflict with this regulation are repealed.
Ingingo ya 21: Ivanwaho ry’ingingo z’amabwiriza zinyuranyije n’aya amabwiriza Article 21: Repealing provisions Article 21: Dispositions abrogatoires Ingingo ya 21: Ivanwaho ry’ingingo z’amabwiriza zinyuranyije n’aya amabwiriza Article 21: Repealing provisions Article 21: Dispositions abrogatoires Ingingo zivanyweho. zose zinyuranye n’aya mabwiriza All previous provisions contrary Regulation are hereby repealed. to this Toutes les dispositions antérieures contraires au présent règlement sont abrogées. - 22 Verify source ↗
Itegurwa, isuzumwa n’iyemezwa
AI-assisted research summary: The regulation was drafted, considered, and approved in English.
Ingingo ya 22: Itegurwa, isuzumwa n’iyemezwa ry’aya mabwiriza rusange Article 22: Drafting, consideration and approval of this Regulation Article 22: Initiation, examen et approbation du présent Règlement Ingingo ya 22: Itegurwa, isuzumwa n’iyemezwa ry’aya mabwiriza rusange Article 22: Drafting, consideration and approval of this Regulation Article 22: Initiation, examen et approbation du présent Règlement Aya mabwiriza rusange yateguwe, asuzumwa kandi yemezwa mu rurimi rw’icyongereza. This Regulation was drafted, considered and approved in English. Le présent Règlement a été initié, examiné et approuvé en anglais. 136 Official Gazette n° 6bis of 05/02/2018 - 23 Verify source ↗
Igihe aya mabwiriza atangirira
AI-assisted research summary: This regulation starts on the day it is published in the Official Gazette of the Republic of Rwanda.
Ingingo ya 23: Igihe aya mabwiriza atangirira gukurikizwa Article 23: Commencement Article 23: Entrée en vigueur 103 AMABWIRIZA RUSANGE No 02/2018 YO KU WA /24/01/2018 YEREKEYE UMUTEKANO W’IBIJYANYE N’IKORANABUHANGA MU ITANGAZABUMENYI N’ITUMANAHO Ishingiye ku Itegeko n° 48/2017 ryo kuwa 23/09/2017 rigenga Banki Nkuru y’u Rwanda, cyane cyane mu ngingo yaryo ya 6, iya 8, iya 9, n’iya 10; Ishingiye ku Itegeko n° 47/2017 ryo ku wa 23/094/2017 imitunganyirize y’imirimo y’amabanki, cyane cyane mu ngingo yaryo iya 37 n’iya 117 ; rigena Official Gazette n° 6bis of 05/02/2018 REGULATION No 02/2018 OF 24/01/2018 ON CYBERSECURITY REGLEMENT No 02/2018 DU 24/01/2018 SUR LA CYBERSECURITE to Pursuant of 23/09/2017governing the National Bank of Rwanda, especially in Articles 6, 8, 9 and 10; 48/2017 Law n° Vu la loi n ° 48/2017 du 23/09/2017 régissant la Banque Nationale du Rwanda, spécialement en ses articles 6, 8, 9 et 10 ; Pursuant to Law n° 47/2017 of 23/094/2017 governing the organization of banking, especially in its Article 37 and 117 ; Vu la loi n° 47/2017 du 23/094/2017 portant organisation de l’activité bancaire, en particulier en son article 37 et 117 ; Banki Nkuru y’u Rwanda, yitwa “ Banki Nkuru” mu ngingo zikurikira itegetse: The National Bank of Rwanda hereinafter referred to as “Central Bank”, decrees: La Banque Nationale du Rwanda ci-après dénommée “ Banque Centrale”, édicte: UMUTWE WA MBERE: INGINGO RUSANGE CHAPTER ONE: GENERAL PROVISIONS CHAPITRE PREMIER: DISPOSITIONS GENERALES Ingingo ya 23: Igihe aya mabwiriza atangirira gukurikizwa Article 23: Commencement Article 23: Entrée en vigueur Aya mabwiriza atangira gukurikizwa ku umunsi atangarijweho mu igazeti ya Leta ya Repubulika y’u Rwanda. This regulation shall come into force on the date of its publication in the Official Gazette of the Republic of Rwanda. Le présent règlement entre en vigueur le jour de sa publication au Journal Officiel de la République du Rwanda. Bikorewe i Kigali, ku wa 24/01/2018 Done at Kigali, on 24/01/2018 Fait à Kigali, le 24./01/2018 (sé) RWANGOMBWA John Guverineri (sé) RWANGOMBWA John Governor (sé) RWANGOMBWA John Gouverneur 137 Official Gazette n° 6bis of 05/02/2018 APPENDIX A (Bank Name) Date_ _ Certification of Compliance with National Bank of Rwanda Cybersecurity Regulation The Board of Directors [or a Senior Officer(s) of the bank] certifies: (1) The Board of Directors (or name of Senior Officer(s)) has reviewed documents, reports, certifications and opinions of such officers, employees, representatives, outside vendors and other individuals or entities as necessary; (2) To the best of the Board of Directors [or name of Senior Officer(s)] knowledge, the Cybersecurity Program of (name of Bank) as of ____/_____/_______ (date of the Board Resolution or Senior Officer(s)) Compliance Finding for the year ended /____/________________(year for which Board Resolution or Compliance Finding is provided) complies with this Regulation (regulation nymber). Signed by the Chairperson of the Board of Directors (or the CEO) (Name) Date: 138
Provision text is displayed from LexChat’s stored statute record. Use the official source links to verify amendments, commencement, and current legal force.
Ask AI about this statute
REGULATION No 02/2018 OF 24/01/2018 ON CYBERSECURITY
Sign in to ask AI about this statute
Sign in to start authenticated, citation-grounded statute research.
Sign in