Argentina: Central Bank Communication 'A' 7724 – Minimum requirements for the management and control of information technology and security risks

In brief

The Argentine Central Bank (ACB) issued Communication 'A' 7724 ("Communication"), which updated the technology and information security risk standards to strengthen the cyber resilience of financial institutions. The Communication will become effective on 6 September 2023.


Contents

In focus

The Communication approves new rules on "minimum requirements for the management and control of information technology and security".

Generally, the ACB aims for regulated entities (financial institutions) to develop and implement governance programs that include, among other things, the following: (i) risk identification and management; (ii) design of internal policies and procedures; (iii) continuous evaluation and audit of policies to identify and correct errors; (iv) internal awareness and training; and (v) proper documentation and backup of data and information, as well as of any security incident or event.

To this end, financial institutions must implement effective control and management practices in accordance with the complexity of the financial services offered and the technology used. Among others, they must do the following:

  • Create a department or role that manages risks related to information technology and security, and develop a strategy aligned with the entity's operations, processes and structure. 
  • Classify data and information considering the following criteria: integrity, availability, confidentiality and value it has for the business. 
  • Document the purpose of using, by themselves or by third parties, a software with artificial intelligence or machine learning algorithms.
  • Implement a process for the management of technological infrastructure updates, as well as online security processes.
  • Make backup copies to ensure the availability and integrity of data and information systems, establishing retention periods for historical backup copies based on legal and regulatory requirements.
  • Implement actions for the detection and deletion of unauthorized profiles in, among others, social networks and e-commerce platforms.
  • Develop cyber incident management policies, including roles and responsibilities of the areas involved in their response, and keep a complete record of the cyber incidents suffered in such a way that allows the identification, traceability and evidence of the actions taken until their closure. In terms of communication and notification, they should establish effective procedures for timely and planned response, as well as designate a point of contact for reporting cyber incidents and mitigate the impact in a timely manner. 

Finally, the Communication also establishes requirements applicable to the outsourcing or delegation to third parties of certain processes, services and/or activities related to information technology and security processes.

Click here to read the Spanish version.


Copyright © 2024 Baker & McKenzie. All rights reserved. Ownership: This documentation and content (Content) is a proprietary resource owned exclusively by Baker McKenzie (meaning Baker & McKenzie International and its member firms). The Content is protected under international copyright conventions. Use of this Content does not of itself create a contractual relationship, nor any attorney/client relationship, between Baker McKenzie and any person. Non-reliance and exclusion: All Content is for informational purposes only and may not reflect the most current legal and regulatory developments. All summaries of the laws, regulations and practice are subject to change. The Content is not offered as legal or professional advice for any specific matter. It is not intended to be a substitute for reference to (and compliance with) the detailed provisions of applicable laws, rules, regulations or forms. Legal advice should always be sought before taking any action or refraining from taking any action based on any Content. Baker McKenzie and the editors and the contributing authors do not guarantee the accuracy of the Content and expressly disclaim any and all liability to any person in respect of the consequences of anything done or permitted to be done or omitted to be done wholly or partly in reliance upon the whole or any part of the Content. The Content may contain links to external websites and external websites may link to the Content. Baker McKenzie is not responsible for the content or operation of any such external sites and disclaims all liability, howsoever occurring, in respect of the content or operation of any such external websites. Attorney Advertising: This Content may qualify as “Attorney Advertising” requiring notice in some jurisdictions. To the extent that this Content may qualify as Attorney Advertising, PRIOR RESULTS DO NOT GUARANTEE A SIMILAR OUTCOME. Reproduction: Reproduction of reasonable portions of the Content is permitted provided that (i) such reproductions are made available free of charge and for non-commercial purposes, (ii) such reproductions are properly attributed to Baker McKenzie, (iii) the portion of the Content being reproduced is not altered or made available in a manner that modifies the Content or presents the Content being reproduced in a false light and (iv) notice is made to the disclaimers included on the Content. The permission to re-copy does not allow for incorporation of any substantial portion of the Content in any work or publication, whether in hard copy, electronic or any other form or for commercial purposes.