Reported Incidents of Fraudulent E-mails and Websites
BANGKo SENTReL NG PILIPINAS OFFICE OF THE DEPUW GOVERNOR SUPERVISION AN D EXAMINATION SECTOR MEMORANDUM NO. M-2OL7 -M To AtL BSP.SUPERVISED INSTITUTIONS Subject REPORTED INCIDENTS OF FRAUDUTENT E.MAItS AND WEBSITES In response to the growing concerns on cyber-attacks involving fraudulent e-mails and websites aimed at customers and employees of financial institutions, BSP- Supervised Financial Institutions (BSFls) are advised to sustain resilience efforts and continue to perform rigorous risk assessments of their current technology environment. Further, BSFIs should ensure compliance with the following BSP issuances: 1. BSP Circular No. 958 dated 25 April 2OL7 Adoption of Multi-Factor Authentication (MFA) Measures for Transactions Considered as Sensitive Communications and/ or High-Risk; and 2. Memorandum No. M-2015-025 dated 22 June2OL5 - Guidance on Management of Risks Associated with Fraudulent E-mails or Websites. In addition to implementing risk-based authentication methods for customer accounts, BSFIs should also ensure adequate access control measures are in place for systems that support the provision of electronic products and services [e.g. authentication servers, application servers, domain name system (DNS) including domain registry services] regardless of whether these are managed internally or by a third-party service provider. For outsourced systems, BSFls, as part of their outsourcing risk management framework, should have a sufficient level of assurance that the service provider is maintaining robust security controls. Stronger authentication methods (other than the use of passwords) should be adopted for high-risk/sensitive systems that are managed by privileged users {e.g. network and system administrators). Accordingly, BSFIs should be guided by ltem 3.2.3 (Security Administration and Monitoring) and ltem 3.2.4 (Authentication and Access Control)of Appendix 75b of the MORB and Appendix Q-59b of the MORNBFt. BSFIs should also be mindful of domain hijacking, whereby attackers modify a BSFI's domain name records to redirect users to unauthorized websites. In such cases, additional security measures such as registry lock featurel (for top-level domain) and MFA should be adooted. ' A measure which enforces manual verification and authentication of all change requests by the top level domain registrar
Further, BSFIs should actively promote a security conscious environment through security awareness and training programs for all personnel and, where relevant, contractors and third-party users in accordance with ltem 3.2.10 (Personnel Security) of Appendix 75b of the MORB and Appendix Q-59b of the MORNBFI. For compliance. ESTOR A. ESPENIT Deputy Governo lO May 2017
More in BSP Memoranda
- Phase out of Bangko Sentral's fiscal agency functions and the transfer of the same to the Department of Finance (DOF)(BSP Memoranda)
- Guidelines on the Electronic Submission of the Annual Report and Audited Financial Statements(BSP Memoranda No. M-2020-060)
- MB Resolution No. 1067 dated 5 July 2012 Placement of the Rural Bank of Badiangan (Iloilo), Inc. under Receivership(BSP Memoranda No. M-2012-033)
- New Amended Joint Order No. 1-91 on CISS(BSP Memoranda)
- Live Implementation of the Enhanced Comprehensive Credit and Equity Exposures Report of 2023 (COCREE 2.0)(BSP Memoranda No. M-2026-020)
- Guidelines on the Electronic Submission of the BASEI III Net Stable Funding Ratio (NSFR) Report(BSP Memoranda No. M-2019-003)
- Third Party Custodianship - Special Power of Attorney (SPA) for Investor-Clients(BSP Memoranda No. M-2006-002)
- Lebanese Currency Exchange Facility for Overseas Filipino Workers Returning from Lebanon(BSP Memoranda No. M-2006-016)
Want an analysis of this document?
Ask ASG Legal AI to summarize it, compare it with other rulings, or explain how it applies to your situation — it researches from this same library.