Skip to main content

Enhanced Guidelines on Information Security Management, Bangko Sentral ng Pilipinas Circular No. 982, Series of 2017

The Circular requires Bangko Sentral Supervised Financial Institutions (BSFIs) to establish an effective and robust information technology (IT) process, governance structure and cybersecurity controls. The Circular outlined the general description of the IT risk profile of all BSFIs which shall be determined and categorized by the Bangko Sentral ng Pilipinas according to the following parameters: 

  • IT infrastructure and operations
  • Digital/electronic financial products and services
  • IT projects and initiatives
  • Outsourced services, 
  • Systematic importance
  • Threats

BSFIs are further required to adopt the Information Security Risk Management Framework to manage information security risks.