Central Bank Sets Data Security Rules for Credit Guarantee Companies
The Central Bank of Egypt has required credit guarantee companies to establish secure technology infrastructure, protect information systems and databases, maintain business continuity plans, and keep their databases inside Egypt under the financial and banking sector’s cybersecurity framework.
Technology and Cybersecurity Requirements
The rules require companies to provide the technology infrastructure needed to establish, operate and secure information systems and databases, while maintaining separation between production and testing environments and taking measures to protect the confidentiality of information and data.
Companies must also provide secure communication channels for exchanging information and data with banks and credit providers, as well as systems to secure access to company systems and databases and plans for responding to security breaches.
Backup Systems and Business Continuity
The rules require companies to maintain regular backups and establish plans to restore information and data during emergencies, reducing the risk of loss or damage.
They must also establish an alternative emergency center at an appropriate distance from the main center as part of their business continuity plans. Employment contracts must include provisions requiring staff to maintain the confidentiality of company information and data.
Companies are also required to establish operational controls governing database access privileges and specify appropriate penalties for violations.
Malware Protection and Penetration Testing
The rules require companies to deploy and continuously update antivirus and anti-malware programs across all systems. They must also maintain documented manuals covering work policies and procedures and review them annually.
In addition, companies must establish mechanisms for managing, addressing and escalating adverse events to the board of directors and senior management within an appropriate timeframe.
Security measures covering information, data, systems and communications networks must be reviewed regularly, including penetration testing and vulnerability assessments to identify and address security gaps. Companies remain responsible for errors arising from the operation and processing of information and data.
Databases to Remain in Egypt
Credit guarantee companies are required to keep their databases within the Arab Republic of Egypt, ensuring that the data remains subject to the country’s regulatory framework and applicable rules.
