Learning Objectives:

  • Understand the key regulatory compliance requirements for cybersecurity.

  • Identify the requirements of PCI-DSS for payment card data security.

  • Explain the SWIFT Customer Security Controls Framework.

  • Recognise the implications of data protection laws for cybersecurity.

6.1 PCI-DSS Requirements

The Payment Card Industry Data Security Standard (PCI DSS) is a set of security requirements for organisations that handle payment card data. The IT Security Controls book includes PCI DSS as a key regulatory framework .

PCI DSS Goals and Requirements:

Goal 1: Build and Maintain a Secure Network

  • Install and maintain a firewall configuration to protect cardholder data.

  • Do not use vendor-supplied defaults for system passwords and other security parameters.

Goal 2: Protect Cardholder Data

  • Protect stored cardholder data.

  • Encrypt transmission of cardholder data across open, public networks.

Goal 3: Maintain a Vulnerability Management Program

  • Protect all systems against malware and regularly update anti-virus software or programs.

  • Develop and maintain secure systems and software.

Goal 4: Implement Strong Access Control Measures

  • Restrict access to cardholder data by business need to know.

  • Identify and authenticate access to system components.

  • Restrict physical access to cardholder data.

Goal 5: Regularly Monitor and Test Networks

  • Track and monitor all access to network resources and cardholder data.

  • Regularly test security systems and processes.

Goal 6: Maintain a Policy That Addresses Information Security

  • Maintain a policy that addresses information security for all personnel.

6.2 SWIFT Customer Security Controls Framework

The SWIFT Customer Security Controls Framework (CSCF) is a set of security controls for SWIFT users. The IT Security Controls book includes the SWIFT CSCF as a key regulatory framework .

Key SWIFT CSCF Controls:

  • Security Governance: Establish a security governance framework.

  • Access Control: Control access to SWIFT systems and data.

  • Separation of Duties: Ensure separation of duties for SWIFT-related activities.

  • Malware Protection: Protect SWIFT systems from malware.

  • Vulnerability Management: Manage vulnerabilities in SWIFT systems.

  • Incident Management: Establish incident management procedures.

6.3 Data Protection Laws

Data protection laws impose requirements for the protection of personal data. The Central Bank of Nigeria’s Framework considers the requirements of the Nigerian Data Protection Act (NDPA) 2023 .

Key Data Protection Requirements:

  • Data Classification: Classifying data based on sensitivity and criticality.

  • Access Control: Restricting access to personal data to authorised personnel.

  • Encryption: Encrypting personal data in transit and at rest.

  • Breach Notification: Notifying regulators and affected individuals of data breaches.

  • Data Retention: Retaining personal data only for as long as necessary.

6.4 Compliance Monitoring and Reporting

The Central Bank of Nigeria’s Framework requires quarterly reports detailing the overall status of the cybersecurity programme, including the status of compliance with Board-approved cyber risk thresholds . This ensures that compliance with regulatory requirements is monitored and reported.

The BSP’s Cybersecurity Maturity Framework requires financial institutions to conduct periodic and rigorous self-assessment exercises as part of their information security risk management system . The assessments are conducted through the Cybersecurity Control Self-Assessment (CCSA) tool . Institutions are classified under four maturity levels: foundational, established, managed, and optimized .