In accordance with the requirements of the National Bank of Georgia (NBG) and industry standards (NIST, ISO 27001, OWASP), the "Cybersecurity, Pentesting, and Vulnerability Scanning" service encompasses technical-practical as well as documentary and organizational components.
Here is what this direction covers in detail:
Penetration Testing (Pentesting) Plan and Execution
External & Internal Pentest: Simulated cyberattacks on VASP web applications, mobile apps, APIs, servers, and network infrastructure to detect vulnerabilities.
Annual Testing of Critical Systems (Clause 10-a): Conducting tests at least once a year on all critical and related information systems (e.g., crypto-wallet management systems, transaction core, KYC/AML databases).
3-Year Rotation for Non-Critical Systems (Clause 10-b): Defining a risk-based plan for non-critical systems to ensure that even low-resource infrastructure is reassessed at least once every 3 years.
Ad-hoc Pentesting upon Major Changes (Clause 11): Re-performing penetration testing whenever major releases, updates, or substantial changes are made to the infrastructure, architecture, or critical software.
Vulnerability Assessment Protocol
Periodic Automated Scanning (Clause 12): Scanning all systems not covered by pentesting in the current year at least twice annually (once every 6 months).
Use of Licensed Scanners: Implementing and configuring internationally recognized tools (e.g., Nessus, Qualys, OpenVAS) to ensure timely identification of known vulnerabilities (CVEs).
CVSS Risk Assessment and Prioritization: Classifying detected vulnerabilities (Critical, High, Medium, Low) and drafting a remediation action plan.
Technological Infrastructure Security and Access Control (Clause 7)
Authentication and Authorization Protection: Auditing and implementing protocols for the secure storage and transmission of passwords, usernames, API keys, and 2FA/MFA tokens.
Protection against Unauthorized Data Alteration: Safeguarding systems against tampering, unauthorized code injection, and errors caused by staff negligence.
Backup Security: Enforcing backup encryption, access restrictions, and periodic verification of data integrity.
Cyber Incident Response and Disaster Recovery (DRP)
Cyber Incident Response Plan (CIRP): Step-by-step operational instructions for the IT team, management, and security personnel during a cyberattack, data breach, or DDoS attack.
Disaster Recovery Plan (DRP): Developing and testing technical scenarios for restoring critical IT infrastructure in the shortest possible timeframe.
