Belize: Technical Assistance Report—Cybersecurity, Regulation, Supervision, and Resilience
IMF Staff Country Reports, September 25, 2020
Source details
- Canonical URL
- Belize: Technical Assistance Report—Cybersecurity, Regulation, Supervision, and Resilience
Other formats
Bibliographic details
- Published: September 25, 2020
- Series: IMF Staff Country Reports
- DOI: https://doi.org/10.5089/9781513557441.002
Summary findings
- Cybersecurity risk is embedded in the CBB’s supervisory framework, but additional enhancements are needed to formalize guidance and develop more intensive supervisory practices.
- Supervisory expectations on cybersecurity are presented in an informal guidance note, which should be formalized into regulation to ensure enforceability.
- An IT/cybersecurity supervisory manual should be developed to promote effective and consistent practices.
- The CBB’s principle-based guidance note highlights priorities for strengthening the cybersecurity posture of Belizean financial institutions and is an appropriate interpretation of international best practices on incident prevention, detection, response, and recovery measures.
- The principles are adapted to the cyber maturity of the Belizean financial institutions and can be used as a foundation for formalized guidelines.
- The proposed supervisory manual could emphasize:
- review of cybersecurity strategies, policies, and responsibility specifications; and
- obtaining assurance on the effectiveness of financial institutions’ processes for cyber risk identification, assessment, and mitigation.
Supervisory framework and guidance
- Current presentation of supervisory expectations:
- Informal guidance note (principle-based).
- Identified gaps:
- Lack of formalized regulation to ensure enforceability.
- Need for a dedicated IT/cybersecurity supervisory manual to promote consistent supervisory practices.
- Areas the manual should address:
- Review of cybersecurity strategies and policies.
- Clear specification of responsibilities.
- Assurance procedures for cyber risk identification, assessment, and mitigation.
Policy recommendations
- Formalize the existing informal guidance note into regulation to ensure enforceability.
- Develop an IT/cybersecurity supervisory manual to:
- Promote effective and consistent supervisory practices.
- Emphasize the review of cybersecurity strategies, policies, and responsibility specifications.
- Address obtaining assurance on the effectiveness of financial institutions’ cyber risk processes.
Content in this bundle
- 1blzea2020002