Monday , March 17 2025
bd bank

Bangladesh Bank published draft “Cyber Security Framework” V.1.0

Banks and financial institutions are undergoing rapid digital transformation, which has improved customer services. However, this shift has also increased cyber threats and vulnerabilities. As a result, cyber resilience is crucial to protect financial systems.

Bangladesh Bank, in its role as a regulator, has unveiled a Cyber Security Framework V- 1.0 specifically tailored for banks and financial institutions under its jurisdiction. This initiative aims to enhance cyber security governance and fortify defenses against cyber threats. The framework is structured around five essential pillars of the NIST Cyber Security Framework: Identify, Protect, Detect, Respond, and Recover.

AWS SNS misused for Data Exfiltration and Phishing

A recent report from Elastic reveals that threat actors misuse Amazon Web Services (AWS) Simple Notification Service (SNS) for malicious...
Read More
AWS SNS misused for Data Exfiltration and Phishing

Researcher found non protected database form ESHYFT containig 86000 records

Cybersecurity researcher Jeremiah Fowler found and reported a non-password-protected database with over 86,000 records belonging to ESHYFT, a New Jersey-based...
Read More
Researcher found non protected database form ESHYFT containig 86000 records

CVE-2024-55591 and CVE-2025-24472
New SuperBlack ransomware exploits Fortinet flaws

Forescout Research- Vedere Labs identified a series of intrusion based on two Fortinet vulnerabilities which began with the exploitation of...
Read More
CVE-2024-55591 and CVE-2025-24472  New SuperBlack ransomware exploits Fortinet flaws

CVE-2025-25291 & CVE-2025-25292
Attention! GitLab Patched Critical Authentication Bypass Flaws

GitLab has released versions 17.9.2, 17.8.5, and 17.7.7 for its Community and Enterprise Editions to fix security vulnerabilities, including a...
Read More
CVE-2025-25291 & CVE-2025-25292  Attention! GitLab Patched Critical Authentication Bypass Flaws

CVE-2025-20138
Cisco released High Security Alert for IOS XR Software

Cisco has issued a security advisory for a high-severity vulnerability in its IOS XR Software, labeled CVE-2025-20138, with a CVSS...
Read More
CVE-2025-20138  Cisco released High Security Alert for IOS XR Software

400+ IPs Exploiting Multiple SSRF Vulnerabilities

GreyNoise warns of a coordinated increase in the exploitation of Server-Side Request Forgery (SSRF) vulnerabilities across various platforms. "At least...
Read More
400+ IPs Exploiting Multiple SSRF Vulnerabilities

NVIDIA has released update for NVIDIA Riva

NVIDIA has released a software update for Riva to fix security vulnerabilities that could allow privilege escalation, data tampering, denial...
Read More
NVIDIA has released update for NVIDIA Riva

CVE-2025-24201
Apple fixes 0-day exploited in “extremely sophisticated attack”

On Tuesday, Apple fixed a critical zero-day vulnerability affecting nearly all supported iPhones and iPads. The company noted that it...
Read More
CVE-2025-24201  Apple fixes 0-day exploited in “extremely sophisticated attack”

Microsoft’s March 2025 updates fix 7 zero-day, 57 flaws

Microsoft's March 2025 Patch Tuesday update fixes 57 flaws, including seven zero-day exploits, six of which are actively being exploited....
Read More
Microsoft’s March 2025 updates fix 7 zero-day, 57 flaws

Ballista Botnet infects 6000 Unpatched TP-Link Routers

Cato CRTL team said, a new botnet campaign dubbed Ballista target the unpatched TP-Link Archer routers. CVE-2023-1389 is a serious...
Read More
Ballista Botnet infects 6000 Unpatched TP-Link Routers

It controls primarily draw from ISO 27001, national ICT Security Policies, and ICT Security Guidelines for Banks and NBFIs, along with other recognized international standards. It’s important to note that this framework establishes baseline cyber security standards and controls intended to meet the minimum safeguarding requirements against cyber threats.

This framework is applicable to banks, non-bank financial institutions (NBFIs), mobile financial service providers (MFSPs), payment service providers (PSPs), payment system operators (PSOs), and other financial service organizations. These entities will collectively be referred to as “The Organization.”

The objectives of this framework are to establish a minimum baseline for management of Cyber Security in the Organization based on the following key areas to:

a) Protecting Financial Stability
b) Detecting and Responding to Cyber Threats
c) Create a common approach for addressing cyber security;
d) Achieve an appropriate maturity level of cyber security practices;
e) Define roles and responsibilities of relevant parties;
f) Address Cyber Security practices with due diligence;
g) Ensure security and privacy requirements;
h) Develop stakeholders‘ awareness to protect information in cyber environment;
i) Ensure a secure environment for data processing;
j) Ensure best practices (industry standard) of the usage of technology.
k) Building a Cyber security Culture

Bangladesh Bank has taken the initiative to accept any suggestions to enrich the “Cyber ​​Security Framework for Banks and Non-Bank Financial Institutions” version 1.0 draft.

The prepared draft framework has already been uploaded on Bangladesh Bank website https://www.bb.org.bd/en/index.php/about/draftguide.

Anyone can suggest any through e-mails at ([email protected] and [email protected]) by 08/10/2024.

Check Also

“Workshop on Cybersecurity Awareness and Needs Analysis” held at BBTA

A time-demanding workshop on “Cybersecurity Awareness and Needs Analysis” was held on Thursday (December 19) …

Leave a Reply

Your email address will not be published. Required fields are marked *