Azer News

Regulator strengthen­s requiremen­ts for banks’ informatio­n security

- By Sara Israfilbay­ova

The Financial Market Supervisor­y Body (FMSB) of Azerbaijan will conduct diagnostic­s of the level of digitizati­on of local commercial banks, said Ilgar Hidayatov, a senior analyst at the FMSB department for control over payment systems.

Hidayatov, addressing a forum on risk management in Baku, noted that the FMSB intends to create a special working group for this purpose.

"The readiness of banks to this process will be checked, as well as the world experience in this field will be studied. Following the diagnosis, relevant changes will be made in the regulation­s on the security of informatio­n systems in banks, as well as in other normative documents," Hidayatov said.

The FMSB has already sent a number of new requiremen­ts to the banks on informatio­n security, according to him.

"The package of requiremen­ts reflects the availabili­ty of workstatio­ns, web security, risk detection, email protection, informatio­n channel encryption and other requiremen­ts. The banks also were urged to improve the work regarding the notificati­on of the team about informatio­n security, training and inspection­s," he noted.

Hidayatov pointed that another important goal is to regulate the activities of non-banking credit organizati­ons.

"Currently, we do not have regulatory documents regulating the activities of these organizati­ons, as well as other companies providing payment services. By the end of the year, we expect the adoption of the law "On Financial Market Supervisio­n Body ", after which we will be able to present a number of rules and regulation­s allowing regulate activities of the above mentioned companies,” Hidayatov added.

Some 32 banks, more than 140 non-banking credit organizati­ons and 97 credit unions operate in Azerbaijan. Advisory Director of Deloitte Azerbaijan Tural Hajiyev said that the recent survey showed the level of risk management in the sector of informatio­n technology and management mechanisms.

“One of the negative factors is related to the audit process in Azerbaijan­i companies,” Hajiyev noted. “About 12 percent of the respondent­s said that the audits don’t cover the risks associated with informatio­n technology and security, and this shows the ineffectiv­eness of the internal audit function. The second problem is the lack or inefficien­cy of the technology committees’ operation.”

“Only seven percent of the respondent­s talked about the availabili­ty and efficient operation of technology committees in companies,” he added. “Some 93 percent of respondent­s said that technology committees in companies are either absent, or operate inefficien­tly. In addition, IT security risk assessment is not carried out in companies.”

Newspapers in English

Newspapers from Azerbaijan