REGULATION No 02/2018 OF 24/01/2018 ON CYBERSECURITY | 02/2018 OF 24/01/2018 — Rwanda law | Esheria

REGULATION No 02/2018 OF 24/01/2018 ON CYBERSECURITY

This regulation says its purpose is to set minimum prudent standards for banks to protect against cybersecurity threats and to promote protection of customer information and banks’ information technology systems.

AI-assisted research synopsis — verify against the official legal text below.

Jurisdiction
Rwanda
Instrument
Regulation
Citation
02/2018 OF 24/01/2018
Status
Not in force
Version
Undated source snapshot
Language
mul
Updated
Official source
View official record ↗
IT oversight access control annual compliance certification audit trails authentication bank compliance banking board governance business continuity planning compensating controls customer data protection customer registration cybersecurity cybersecurity controls cybersecurity program data classification data localization data retention policy deadline compliance definitions documentation on request drafting and approval process encryption exemptions +27 more

Statute overview

About this statute

This regulation says its purpose is to set minimum prudent standards for banks to protect against cybersecurity threats and to promote protection of customer information and banks’ information technology systems. This article defines key terms used in the regulation. Banks licensed by the Central Bank must keep their primary data in Rwanda. Banks must set up cybersecurity governance, including board responsibility, an IT committee, and an IT security unit. Banks must maintain a cybersecurity strategy and program and provide related documents to Banki Nkuru when requested.