Electronic Safety and Soundness in Colombia Financial Sector Policy Global Dialogue Series #19 Milton Quiroga
Trends in e-security incidents in Banking in Colombia Malicious code, virus, worms, chain-letters are daily problems, Companies are ill-prepared for incident handling: –No formal procedures for incident handling, Usually based on tips interchanged in forums, –No formal procedures for evidence collection, Important black numbers of unpunished crimes, Banks don’t have major incentives to improve its security in e- commerce, –In credit card transactions client (user) is always liable! A growing and undocumented problem: identity theft, –Privacy in Colombia? Of course, spamming is also a growing (and annoying) problem,
Processes to mitigate electronic security risks In Colombia risk management is usually an auditor problem, –Computer security is not a mainstream problem for employees, In general computer security is not part of the organizational culture, We are using technological and management tools to improve our security: –PKI, smart-cards, … –BCP/DRP, role separation, risk management, … –However, these topics are still “esoteric” for many Colombian banks, A big challenge: keep our systems up to date!
Role of multilateral institutions UNCITRAL wrote a “model law” for e-commerce and digital signatures that several countries adopted and adjusted to its necessities: –v.g Colombia in 1999, It’s desirable to have a “model law” based on “civil law” (not “common law”): –Computer crime (electronic vandalism, identity theft, DoS, …), –Transnational issues, –Privacy, –Spamming, –…