Cybersecurity Guidelines for Financial Sector Te…

Cybersecurity Guidelines for FSTI Providers

3.2. Information Security Principles

The fundamental framework to safeguard information security covers Confidentiality, Integrity, and Availability (CIA).

3.2.1. Confidentiality

All sensitive data should be encrypted using advanced cryptographic standards to ensure that data remains secure even if accessed by unauthorised entities. FSTI Providers implement strong encryption standard AES-256 1 or at least AES-128 as recommended by the National Cyber and Crypto Agency (BSSN).

1.

Encryption

a) Encryption Standards - Encryption data at rest using industry-standard algorithms such as AES (Advanced Encryption Standard) AES-128 as per the minimum recommendation by BSSN. Employ TLS 1.2 or higher for encrypting data in transit to ensure secure data exchange between clients and servers. 2 b) Encryption Implementation - Apply encryption to all sensitive data, including personal identification information, transaction details, and financial records. - Ensure that encryption keys are securely managed, with key generation, distribution, storage, rotation, and destruction procedures in place to prevent unauthorised access.

1 Advanced Encryption Standard (AES), https://www.techtarget.com/searchsecurity/definition/ Advanced-Encryption-Standard 2 Advanced Encryption Standard (AES) - National Institute of Standards and Technology (NIST), https:// www.nist.gov/publications/advanced-encryption-standard-aes

24

Made with FlippingBook. PDF to flipbook with ease