Document from CIS Legislation database © 2012-2026 CIS Legislation Company

RESOLUTION OF BOARD OF NATIONAL BANK OF THE REPUBLIC OF BELARUS

of July 7, 2026 No. 164

About approval of the standard of financial services and technologies

Based on the paragraph of the fifty seventh of Article 26 and part one of article 39 of the Bank code of the Republic of Belarus the Board of National Bank of the Republic of Belarus DECIDES:

1. Approve the standard of financial services and SFUT 9.05-2026 technologies "Banking activity. Ensuring information security. Assessment of level of compliance of information security of banks to requirements of SFUT 9.03-2025" (is applied).

2. This resolution becomes effective since January 1, 2027.

Chairman of the board

R.A.Golovchenko

 

No. 164 is approved by the Resolution of Board of National Bank of the Republic of Belarus of July 7, 2026

Standard of financial services and SFUT 9.05-2026 technologies "Banking activity. Ensuring information security. Assessment of level of compliance of information security of banks to requirements of SFUT 9.03-2025"

Chapter 1. General provisions

1. This standard of financial services and technologies (further – the standard) extends to banks, the non-bank credit and financial organizations and "Development Bank of the Republic of Belarus" open joint stock company (further – banks), and also to the organizations which are carrying out assessment of level of compliance of information security (further – IB) banks to requirements of the standard of financial services and SFUT 9.03-2025 technologies "Banking activity. Ensuring information security. General requirements", the Board of National Bank of the Republic of Belarus approved by the resolution of December 29, 2025 No. 390 (further – SFUT 9.03-2025).

2. This standard is intended for application by inclusion of references to it and (or) the requirements established in it in local legal acts of banks, and also in agreements.

3. In case of application of this standard it is necessary to observe requirements of the legislation on information, informatization and information security, including regulatory legal acts of National Bank and technical regulatory legal acts, obligatory for observance (further – TNPA).

4. In this standard terms in the values established in standards of financial services and SFUT 9.01-2024 technologies "Banking activity are used. Ensuring information security. General provisions and terminology", SFUT 9.02-2024 "Banking activity. Ensuring information security. Requirements to documentation on ensuring activities in information security field", No. approved by the resolution of Board of National Bank of the Republic of Belarus of June 20, 2024 185, and SFUT 9.03-2025, other regulatory legal acts of National Bank.

Chapter 2. Indicators of Ib. Methods of estimation of indicators

5. For assessment of level of compliance of IB of bank to requirements of SFUT 9.03-2025 (further – compliance level assessment) indicators of IB Mij which are presented in the questionnaire form with questions, answers to which allow to perform their assessment of G where, are used:

i – number of the direction of information security system (further – SIB) or requirements of system of management of information security (further – SMIB);

j – number of indicator of IB of the SIB direction or requirement of SMIB.

The questionnaire form intended for filling when evaluating level of compliance is given in appendix.

6. Assessment G indicators of IB Mij is performed based on the established checking group (person) or the auditor of extent of fulfillment of requirements of SFUT 9.03-2025 by means of qualified assessment.

Estimation of indicator of IB Mij is performed by putting down of symbol "H" in the corresponding column of form of the questionnaire.

7. For indicators of IB the following scale of extent of their accomplishment is established:

"is not carried out" – the value equal 0 is appropriated to assessment;

"it is carried out partially" – 0,5 or 0,75 0,25, value is appropriated to assessment;

"is carried out" – the value equal 1 is appropriated to assessment.

If the indicator of IB is intended for assessment of requirements which at the time of assessment of level of compliance are not urgent for bank (because of technical impossibility or economic inexpediency of implementation of requirements) that is reflected in documents of bank, then such indicator of IB is determined as not estimated (the column "N / about" is filled in – there is no assessment) and is not considered in forming of results of final level of compliance of IB of bank to requirements of SFUT 9.03-2025.

8. Depending on contents of the requirement of IB their indicators are estimated on:

dokumentirovannost degrees;

extents of accomplishment of the requirement of IB;

degrees of dokumentirovannost and accomplishment of the requirement of IB.

9. When evaluating indicators for which only dokumentirovannost degree is estimated the following marks are put down:

"0" – requirements of indicator of IB are not established in internal documents of bank;

"1" – requirements of indicator of IB are established in internal documents of bank.

10. When evaluating indicators for which only extent of accomplishment of the requirement of IB is estimated the following marks are put down:

"0" – requirements of indicator of IB are not fulfilled;

"0,5" – requirements of indicator of IB are fulfilled in incomplete amount;

"1" – requirements of indicator of IB are fulfilled in full.

11. When evaluating indicators for which both dokumentirovannost degree, and extent of their accomplishment is estimated the following marks are put down:

"0" – requirements of indicator of IB are not established in internal documents of bank and are not carried out;

"0,25" – requirements of indicator of IB are not established in internal documents of bank, but are carried out in incomplete amount;

"0,5" – requirements of indicator of IB are established in internal documents of bank, but are not carried out;

"0,75" – requirements of indicator of IB are established in internal documents of bank, but are carried out in incomplete amount;

"1" – requirements of indicator of IB are established in internal documents of bank and are carried out in full.

12. Assessment of indicator of IB is based on certificates as which sources are used:

the internal documents of bank and other documents relating to providing IB of bank;

information from employees of bank obtained by results of their interviewing;

results of observations of the checking group (person) or the auditor during evaluating.

13. Sources of the received certificates are documented in the column "Source of Certificates" of form of the questionnaire (internal documents, survey results of employees of bank, observation of the checked faces).

Chapter 3. Establishment of method of estimation of SIB of bank based on assessment of fulfillment of requirements determined in the Section II SFUT 9.03-2025

14. Assessment of implementation of basic requirements to SIB of bank is determined by means of indicators of IB allowing to estimate extent of fulfillment of requirements of IB SFUT 9.03-2025 in the following directions:

ensuring anti-virus protection;

ensuring safe development of the software (further – ON);

safety of the automated workplaces (further – automated workplace);

safety during the work with the global computer Internet (further – the Internet);

safety of the server hardware;

safety of the circle of virtualization;

providing IB of the automated bank system (further – ABS) at stages of its lifecycle;

ensuring cryptographic information security using means of cryptographic information security (further – SKZI);

ensuring physical safety;

training and increase in awareness concerning IB;

prevention of leakages of confidential information;

management of access;

event management and IB incidents;

management of vulnerabilities.

15. Assessment of extent of fulfillment of requirements of SFUT 9.03-2025 for the SIB Ni separate direction is determined as arithmetic-mean G indicators of IB Mij of all estimates entering the SIB this direction and is calculated on formula

164-1

where i – number of the SIB direction (i = [1,14]);

j – number of indicator of IB in the direction of SIB;

n – quantity of all estimated IB indicators in the direction of SIB.

16. If all indicators of IB of the SIB direction intended for assessment of requirements at the time of assessment of level of compliance are not urgent for bank (because of technical impossibility or economic inexpediency of implementation of requirements) that is reflected in documents of bank, then calculation of assessment of extent of fulfillment of requirements of SFUT 9.03-2025 for this SIB direction is not perfromed.

17. Assessment of degree of compliance of requirements of SIB of bank to requirements of SFUT 9.03-2025 LSIB is determined as arithmetic-mean estimates of extent of fulfillment of requirements of all SIB urgent directions and is calculated on formula

164-2

where i – number of the SIB direction;

k – quantity of the SIB urgent directions.

Chapter 4. Establishment of method of estimation of SMIB of bank based on assessment of fulfillment of requirements determined in the Section III SFUT 9.03-2025

18. Assessment of the organization and ensuring functioning of SMIB of bank is determined by means of indicators of IB allowing to estimate extent of accomplishment of SMIB of the following requirements of SFUT 9.03-2025:

requirements to the organization and functioning of division of IB of bank;

requirements to determination of scope of SMIB;

requirements to the choice of approach to risks assessment of IB and evaluating risks of IB;

requirements to development and realization of processing of risks of IB;

requirements to development of the documents regulating activities in the field of providing IB;

requirements to acceptance by management of bank of decisions on realization and operation of SMIB;

requirements to development and program implementation on training and increase in awareness of employees of bank in the field of IB;

requirements to the organization of detection of incidents of IB and response to them;

requirements to the organization of providing continuity of IB and its recovery after failures;

requirements to monitoring and efficiency evaluation of SMIB;

requirements to carrying out internal audit of IB;

requirements to the analysis of functioning of SMIB;

requirements to the analysis of SMIB from management of bank;

requirements to decision making on improvement of SMIB.

19. Assessment of extent of accomplishment of SMIB of the separate requirement of SFUT of 9.03-2025 Ni is determined as arithmetic-mean G indicators of IB Mij of all estimates entering this requirement of SMIB and is calculated on formula

164-3

where i – number of the requirement of SMIB (i = [15,28]);

j – number of indicator of IB in the requirement of SMIB;

n – quantity of all estimated IB indicators in the requirement of SMIB.

20. Assessment of degree of compliance of requirements of SMIB of bank to requirements of SFUT 9.03-2025 LSMIB is determined as arithmetic-mean estimates of extent of accomplishment of all requirements of SMIB and is calculated on formula

164-4

where i – number of the requirement of SMIB.

Chapter 5. Determination of final level of compliance of IB of bank to requirements of SFUT 9.03-2025

21. Final assessment of degree of compliance of requirements of IB of bank to requirements of SFUT 9.03-2025 L is calculated on formula

164-5

22. If assessment of L lies in interval [0;0, 25), then zero level of compliance of IB to requirements of SFUT 9.03-2025 is appropriated.

If assessment of L lies in interval [0,25;0, 5), then is appropriated the first (unsatisfactory) level of compliance of IB to requirements of SFUT 9.03-2025.

If assessment of L lies in interval [0,5;0, 75), then is appropriated the second (satisfactory) level of compliance of IB to requirements of SFUT 9.03-2025.

If assessment of L lies in interval [0,75;0, 85), then is appropriated the third (good) level of compliance of IB to requirements of SFUT 9.03-2025.

If assessment of L lies in interval [0,85;0, 95), then is appropriated the fourth (sufficient) level of compliance of IB to requirements of SFUT 9.03-2025.

If assessment of L lies in interval [0,95; 1], the fifth (high) level of compliance of IB to requirements of SFUT 9.03-2025 is appropriated.

23. The value L received as a result of assessment of extent of fulfillment of requirements is basis for forming of the conclusion by results of compliance level assessment.

24. The system of providing IB of bank is considered organized and functioning in case of achievement of the fourth (sufficient) and the fifth (high) compliance of IB of levels to requirements of SFUT 9.03-2025.

 

Appendix

to the Standard of financial services and SFUT 9.05-2026 technologies "Banking activity. Ensuring information security. Assessment of level of compliance of information security of banks to requirements of SFUT 9.03-2025"

Form

The questionnaire when evaluating level of compliance of IB of bank to requirements of SFUT 9.03-2025

Designation of indicator of IB,
Mij

IB indicator

IB indicator assessment *, G

Source of certificates

0

0,25

0,5

0,75

1

N / about

IB indicators in the SIB direction

Indicators in the direction SIB "Ensuring Anti-virus Protection", M1

M1.1

Whether are applied on all automated workplaces and the ABS servers if other is not provided by bank engineering procedure, means of anti-virus protection

paid document

Full text is available with an active Subscribtion after logging in.

Disclaimer! This text was translated by AI translator and is not a valid juridical document. No warranty. No claim. More info

Search in text CTRL-F

Demo Access

If you are guest on our site, you will work in Demo mode. In Demo mode you can see only first page of each document.


Full Access

With full access you can

  • see full text
  • see original text of document in Russian
  • download attachment (if exist)
  • see History and statistics

Get Full Access Now

Effectively work with search system

Database include more 65000 documents. You can find needed documents using search system.
For effective work you can mix any on documents parameters: country, documents type, date range, teams or tags.
More about search system

Get help

If you cannot find the required document, or you do not know where to begin, go to Help section.

In this section, we’ve tried to describe in detail the features and capabilities of the system, as well as the most effective techniques for working with the database.

You also may open the section Frequently asked questions.
This section provides answers to questions set by users.

Search engine created by CIS Legislation Company