Nepal Rastra Bank (NRB) has formulated the IT policy for own implementation and for all the other licenses bank and financial institutions. NRB also formulate the Nepal Rastra Bank information technology guidelines (NRB IT Guidelines). The main objectives of the NRB IT policy are –
- To ensure secure, stable and standard IT infrastructure.
- To ensure availability, integrity, and confidentiality of information.
- To enhance user awareness for efficient, effective and economic use of the IT system.
- To minimize IT-related risk.
- To facilitate the efficient operation of the information system in the financial sector.
NRB IT Policy
- Ensure efficient, effective and economic IT operation by implementing an appropriate IT system, e.g Financial Information System (FIS), Management Information System (MIS), Enterprise Resource Planning (ERP) System, Real-time Gross Settlement System (RTGS), Scripless Security Settlement System (SSSS), etc.
- Maintain well-structured, secured physical IT infrastructure with proper documentation.
- Maintain multi-level security for information.
- Implement an IT system audit.
- Develop, implement and maintain data backup and recovery policy.
- Establish and maintain efficient, effective and economic Disaster Recovery Planning (DRP) System as an instrument to “Fail-Safe System” with minimum downtime. Also, develop and maintain Business Continuity Planning (BCP).
- Develop and implement IT outsourcing and third-party involvement mechanism.
- Maintain uniform and legitimate IT infrastructure for all the offices.
- Provide IT Directive to licenses bank and financial institutions.
- Set a standard for IT procurement and shall be reviewed as per the technological changes.
- Promulgate” NRB IT Code of conduct” for proper usage of NRB IT resources.
- Strengthen the IT capacity building for employees.
NRB IT Guidelines 2068
The use of information technology by the financial sector has changed the way they are doing business. It has become a part of the business rather than supporting factor for business and has created challenges of managing and governing it. Issues of tackling with changes in limiting access to system and data from one to another, maintain an adequate internal control system, limiting access to system and data from unauthorized access, securing electronic transactions, meeting legal requirements, managing outsourcing services, and managing other IT-related risks have been emerged in the banking sector.
1) IT Governance
- A bank should us IT resources in an efficient, effective, and economical manner so that all business requirements are met.
- IT-related risks should be considered in risk management policy.
- A bank needs to carry out a detail risk analysis before adopting a new technology/system since it can potentially introduce new risk exposure.
- A bank should constantly monitor and measure IT functions and report to an appropriate level of management.
2) Information Security
- A bank should harden its system i.e should be configured with the highest level of security setting on OS, firewall and system software.
- A bank should develop and maintain a comprehensive computer virus protection mechanism.
- A bank should develop strong cryptography and end-to-end encryption to protect customer PINs, user’s password and other sensitive data in network and storage.
- CCTV systems should be installed in all the ATMs with an appropriate lighting system.
- A bank should implement adequate security measures to secure their web applications and databases to protect from cyber threats.
3) Information Security Education
- A bank should develop an information security awareness program and periodically conduct to its employees, vendors, customers, and other concern authorities.
- A bank should ensure that customers are adequately educated so that they can operate banking operations securely.
- A bank should use an appropriate customer authentication system to authenticate customers before the accessing system.
4) Information Disclosure and Grievance Handling
- A bank should publish clear information about the dispute or problem resolution process in case of any security breaches and fraudulent access to a customer’s account.
- A bank should publish customer privacy and security policy, fee & commission on their website.
- A bank shall be responsible for grievance handling in case of customer complaints.
- A bank should provide clear information to their customer about the risks and benefits of using e-banking, online banking, mobile banking.
5) Outsourcing Management
- A bank should ensure that their service providers are capable of delivering the level of performance, service reliability, capability and security needs that are required.
- A bank should evaluate the economic, social and political risk factors before doing an outsourcing agreement.
- A bank should ensure that the availability and quality of the banking services are not adversely affected by the outsourcing agreement.
6) IT Operations
- Board and higher management should oversee the functioning of IT operations and should ensure a safe IT operation environment.
- A bank should be able to ensure that they have adequate recourses in terms of hardware, software, and other operating capabilities to deliver timely, reliable, secure information.
- A bank should conduct a periodic risk assessment of their IT environment.
- There should be documented standards for administering the application system.
7) Disaster Recovery and Business Continuity Planning
- The introduction of the electronic delivery channel and 24/7 service availability has increased the demand for business continuity planning (BCP) framework.
- A BCP should consider all the probable man-made and natural disasters, security threats, regularity requirements, dependencies in outsourcing activities.
- A bank should maintain an efficient, effective and economic disaster recovery system as an instrument to “Fail-Safe System” with minimum downtime.
8) Information System Acquisition, Development, and Implementation
- Many software fails due to inadequate system testing and bad system design.
- An application that handles financial information of customer’s data should inter-alia, satisfy security requirements.
- All the vulnerabilities, loopholes and defects should be fixed before the implementation of the system.
9) Information System Audit
- To ensure the effectiveness of the implemented controls framework and adequacy of the adopted security plan and procedures, a bank should conduct IS audit periodically.
- If the bank does not have enough staff, then an expert from outside the bank should be appointed as an IS auditor.
10) Fraud Management
- A bank should identify and document all the electronic attacks and submit a report to Nepal Rastra Bank.
- Customers should be made aware of fraud along with fraud identification, avoidance and protection measures.
These guidelines to regulate and guide IT-related activities in commercial banks with the objectives o strengthening banks for tackling emerging cyber frauds, managing information technology prudently and mitigating risk aroused from the implementation of information technology.