Cybersecurity, Penetration Testing and Vulnerability Scanning

In accordance with the requirements of the National Bank of Georgia (NBG) and industry standards (NIST, ISO 27001, OWASP), the "Cybersecurity, Pentesting, and Vulnerability Scanning" service encompasses technical-practical as well as documentary and organizational components.

Here is what this direction covers in detail:

  1. Penetration Testing (Pentesting) Plan and Execution

    • External & Internal Pentest: Simulated cyberattacks on VASP web applications, mobile apps, APIs, servers, and network infrastructure to detect vulnerabilities.

    • Annual Testing of Critical Systems (Clause 10-a): Conducting tests at least once a year on all critical and related information systems (e.g., crypto-wallet management systems, transaction core, KYC/AML databases).

    • 3-Year Rotation for Non-Critical Systems (Clause 10-b): Defining a risk-based plan for non-critical systems to ensure that even low-resource infrastructure is reassessed at least once every 3 years.

    • Ad-hoc Pentesting upon Major Changes (Clause 11): Re-performing penetration testing whenever major releases, updates, or substantial changes are made to the infrastructure, architecture, or critical software.

  2. Vulnerability Assessment Protocol

    • Periodic Automated Scanning (Clause 12): Scanning all systems not covered by pentesting in the current year at least twice annually (once every 6 months).

    • Use of Licensed Scanners: Implementing and configuring internationally recognized tools (e.g., Nessus, Qualys, OpenVAS) to ensure timely identification of known vulnerabilities (CVEs).

    • CVSS Risk Assessment and Prioritization: Classifying detected vulnerabilities (Critical, High, Medium, Low) and drafting a remediation action plan.

  3. Technological Infrastructure Security and Access Control (Clause 7)

    • Authentication and Authorization Protection: Auditing and implementing protocols for the secure storage and transmission of passwords, usernames, API keys, and 2FA/MFA tokens.

    • Protection against Unauthorized Data Alteration: Safeguarding systems against tampering, unauthorized code injection, and errors caused by staff negligence.

    • Backup Security: Enforcing backup encryption, access restrictions, and periodic verification of data integrity.

  4. Cyber Incident Response and Disaster Recovery (DRP)

    • Cyber Incident Response Plan (CIRP): Step-by-step operational instructions for the IT team, management, and security personnel during a cyberattack, data breach, or DDoS attack.

    • Disaster Recovery Plan (DRP): Developing and testing technical scenarios for restoring critical IT infrastructure in the shortest possible timeframe.