The Information Security, Personal Data Protection and Classified Information Function (ISF) has full independence and autonomy in its operation and is responsible for ensuring and continuously improving the security of information and information means, for monitoring and controlling the compliance with internal regulations and the operation of the National Bank with the regulations pertaining to protection of personal data and security of classified information, as well as for ensuring business continuity of the National Bank. To this end, the ISF, as an organizational unit of the second line of defense carries out the following activities:
-
risk analysis and proposing mitigation measures;
-
raising awareness among employees, advising and training on the proper implementation of regulations;
-
coordinating the processes for ensuring compliance with the relevant regulations and ensuring business continuity of the National Bank;
-
monitoring / testing / controlling the compliance of acts and operations with the relevant regulations and
-
reporting to top management.
The security management framework is based on:
In the ISF are authorized persons who are responsible for monitoring the compliance of the National Bank with the regulations in the field of:
-
Information security (an information security officer‒ ISO);
-
Personal data protection (a data protection officer ‒ DPO);
-
Classified information security (officer for security of classified information ‒ OSCI) and
-
Ensuring business continuity (business continuity officer - BCO).
The authorized persons act as a contact point of the National Bank with: Personal data subjects regarding the exercising their legal rights; Personal Data Protection Agency, about matters related to personal data processing and protection; Directorate for Security of Classified Information, regarding the security of classified information, as well as with other regulatory authorities and organs.
The implementation of the Information Security Policy in the National Bank is monitored by the Information Security Steering Committee (ISSC). ISSC sets the strategic directions and priorities in the field of information technology and the information security of the National Bank, supervises the development and implementation of the information security strategic plans , reviews and approves the internal regulations for implementation of the Information Security Policy, priorities and major investments in information technology, monitors the status of major IT projects and analyzes and approves requests for exceptions to the Information Security Policy. The manner of operations of NOIS is regulated by Rules of Procedure.
{{Title}}
{{Intro}}
{{{Content}}}
{{#hasElements Images}}
{{#each Images}}
{{#showInline ShowInGallery IsThumbNail}}
{{{dataImg this params="?width=886"}}}
{{/showInline}}
{{/each}}
{{#each Images}}
{{#showInline ShowInGallery IsThumbNail}}
{{{dataImg this params="?width=200&height=100"}}}
{{/showInline}}
{{/each}}
{{/hasElements}}