Purpose

Capture the CBCS information technology guidance suite as a consolidated BCMS source for IT governance, information security, IT service management, safe and sound electronic banking, computer risk management, business continuity and software testing.

Authority

  • Publisher: Centrale Bank van Curacao en Sint Maarten (CBCS)
  • Authority level: CBCS supervisory guidance and memoranda
  • Scope: IT governance, information security, IT service management, electronic banking, computer risk management, business continuity management and software testing
  • Language reviewed: English
  • Local PDF copies reviewed: yes
  • Consolidated source decision: yes

Source Materials Included

RefDocumentVersion or date shownLocal fileBCMS use
IT-001IT Framework Memorandum for Supervised InstitutionsUpdated version April 201120190120_it_framework_memorandum_for_supervised_institutions.pdfIT framework baseline, compliance, IT questionnaire, development and acquisition, outsourcing services
IT-002Policy Memorandum: Management of Computer RisksUpdated version April 201120190120_policy_memorandum_management_of_computer_risks.pdfComputer risk taxonomy, control classes, preventive and containment controls, inspection and audit
IT-003Provisions and Guidelines for Information Security ManagementUpdated version April 201120190120_provisions_and_guidelines_for_information_security_management.pdfSecurity framework, ongoing risk assessment, monitoring, incident response, privacy, training and audit
IT-004Provisions and Guidelines for Safe and Sound Electronic BankingUpdated version April 201120190120_provisions_and_guidelines_for_safe_and_sound_electronic_banking_updated_version_2011.pdfE-banking risk management, internal control, cross-border e-banking, customer security and transparency
IT-005Provisions and Guidelines for Business Continuity ManagementAugust 202120210827_provisions_and_guidelines_business_continuity_management.pdfContext, oversight, business impact analysis, BCPs, training, testing, review and audit
IT-006Provisions and Guidelines for the Governance of Enterprise Information TechnologyAugust 202120211018_provisions_and_guidelines_for_it_governance_2.pdfIT governance framework, value contribution, risk management, capabilities, stakeholder communication and audit
IT-007Provisions and Guidelines for Information Technology Service ManagementVersion July 201420190120_provisions_and_guidelines_for_information_technology_service_management.pdfService management, support, assets, configuration, backup, third-party services, training and audit
IT-008Provisions and Guidelines for Software Testing2024-08-2320240823_provisions_and_guidelines_for_software_testing.pdfTest policy, test strategy, risk-based planning, test design, dedicated test environment, skills, security testing and assessment program

Summary

This source consolidates the CBCS IT and technology guidance that underpins Bitkaya’s enterprise technology, security, continuity and testing expectations. Taken together, the documents establish a supervisory baseline for how an institution should govern IT, secure information assets, manage electronic banking risk, sustain operations, test software changes and maintain resilient services.

The guidance suite is intentionally grouped here because the documents share a common operating domain and are used together in BCMS to support enterprise IT governance, cyber and information security, service management, continuity planning and software-change assurance.

Relevant Provisions

Provision themes identified from the combined guidance:

  • Board and senior-management oversight of IT and security
  • IT governance frameworks, value delivery and stakeholder communication
  • Information security risk assessment, monitoring and incident management
  • Privacy protection and control of customer information
  • IT service management, asset and configuration control, backup and restoration
  • Management of third-party IT services and outsourced technology support
  • Computer risk controls, preventive controls and audit oversight
  • Electronic banking risk management and customer security
  • Business continuity, RTO and RPO planning, training, testing and review
  • Software testing policy, test strategy, planning, execution, security testing and ongoing assessment

Relationships

Assurance

  • CBCS PDFs reviewed: yes
  • Title pages and section headings extracted: yes
  • Consolidated-source decision recorded: yes
  • Requirement-level extraction completed: yes
  • Local PDFs stored in BCMS: no
  • Applicability confirmed: review pending

History

  • 2026-07-26: Created consolidated IT source object from eight CBCS guidance documents covering IT governance, information security, IT service management, electronic banking, computer risk management, business continuity and software testing.
  • 2026-07-26: Extracted source requirements REQ-IT-001 through REQ-IT-008.