Cyber Security Guidelines for BFSI in Bangladesh: A Working Reading
Bangladesh Bank ICT Security Guidelines, the SWIFT CSP, and the operational reality of meeting them inside a regulated financial institution.
Banks and NBFIs operate under several overlapping regimes — BB ICT Guideline, SWIFT CSP, PCI-DSS, and the Data Privacy Act. The internal audit team has to satisfy all of them at once, with one shared evidence pipeline.
Source: Cloud Digit advisory engagements, 2024–2026.
What the technical control surface looks like
Cloud APIs + branch agents + SaaS connectors → single source of truth
Hardware-backed; SMS and OTP retired for admin paths
Time-bound, ticket-bound, and forwarded to immutable storage
Separate VRF / ACL boundary · no overlap with corporate IdP
BB ICT default 1 year online + 5 years archived; immutable bucket
RTO/RPO measured · post-mortem signed by CIO
Independent assessor · evidence stored alongside controls
Source: Cloud Digit shared-responsibility framework mapped to BB ICT domains.