Unofficial translation
This resolution comes into force on January 1, 2021.In accordance with subparagraph 1) of part 1 of Article 13-6 of the Law of the Republic of Kazakhstan dated July 4, 2003 "On state regulation, control and supervision of the financial market and financial organizations", the Board of the Agency of the Republic of Kazakhstan for regulation and development of the financial market DECIDES:
1. To approve the attached Rules for assessment of the level of protection against information security threats. 2. The Cybersecurity Department, in the order established by the legislation of the Republic of Kazakhstan, to ensure:
1) jointly with the Legal Department, a state registration of this resolution in the Ministry of Justice of the Republic of Kazakhstan;
2) posting of this resolution on the official Internet resource of the Agency of the Republic of Kazakhstan for regulation and development of the financial market after its official publication;
3) within ten working days after the state registration of this resolution, submission of information to the Legal Department on implementation of the measure provided for in subparagraph 2) of this paragraph.
3. The supervising Deputy Chairman of the Agency of the Republic of Kazakhstan for regulation and development of the financial market is authorized to control the execution of this resolution.
4. This resolution comes into force on January 1, 2021 and is subject to official publication.
|
Chairperson of the Agency of the Republic of Kazakhstan for regulation and development of financial market |
M. Abylkasymova |
| Approved by the resolution of the Board of the Agency of the Republic of Kazakhstan for regulation and development of financial market dated November 23, 2020 № 110 |
Rules for assessment of level of protection against information security threats
Chapter 1. General provisions
1. These Rules for assessment of the level of protection against information security threats (hereinafter referred to as the Rules) are developed in accordance with the Law of the Republic of Kazakhstan dated July 4, 2003 "On state regulation, control and supervision of the financial market and financial organizations" and determine the procedure for assessment of the level of protection against information security threats of financial organizations and branches of non-resident banks of the Republic of Kazakhstan, branches of insurance (reinsurance) organizations-non-residents of the Republic of Kazakhstan, branches of insurance brokers-non-residents of the Republic of Kazakhstan (hereinafter - financial organizations).
2. The following concepts are used in the Rules:
1) key information systems of a financial organization - information systems of a financial organization necessary for functioning of business processes that implement the main activities of a financial organization;
2) an authorized body - a state body exercising state regulation, control and supervision of the financial market and financial organizations.
Chapter 2. Procedure for assessment of level of protection against threats
3. Assessment of the level of protection against information security threats is carried out by financial organizations at the request of the authorized body.
4. The assessment of the level of protection against information security threats is carried out by the financial organization in accordance with the parameters for assessment of the level of protection against information security threats in accordance with the appendix to the Rules.
For each parameter specified in column 2 of the appendix to the Rules, the financial organization determines one of the levels of security specified in columns 3, 4, 5 of the appendix to the Rules.
5. The assessment of the level of protection against information security threats is drawn up by the financial organization in the form of a table indicating the parameters for assessment of the level of protection against information security threats listed in column 2 of the appendix to the Rules, the level of protection and a brief description of their implementation.
6. The result of assessment of the level of protection against information security threats is approved by the head of the financial organization and provided by the financial organization with a cover letter to the authorized body within a period not exceeding three months from the date of receipt of the request from the authorized body for such an assessment.
7. The results of assessment of the level of protection against information security threats by the financial organization are accompanied by documents confirming the levels of protection 2 and 3 in accordance with the appendix to the Rules.
8. The authorized body checks the results of assessment of the level of protection against information security threats provided by the financial organization for compliance with the attached documents and determines the final level of protection of the financial organization for each of the parameters for assessment of the level of protection against information security threats in accordance with the appendix to the Rules.
9. The final results of assessment of the level of protection of a financial organization against information security threats are brought to the attention of the financial organization by the authorized body.
| Appendix to the Rules for assessment of level of protection against information security threats |
