Purpose
Capture the CBCS information technology guidance suite as a consolidated BCMS source for IT governance, information security, IT service management, safe and sound electronic banking, computer risk management, business continuity and software testing.
Authority
- Publisher: Centrale Bank van Curacao en Sint Maarten (CBCS)
- Authority level: CBCS supervisory guidance and memoranda
- Scope: IT governance, information security, IT service management, electronic banking, computer risk management, business continuity management and software testing
- Language reviewed: English
- Local PDF copies reviewed: yes
- Consolidated source decision: yes
Source Materials Included
| Ref | Document | Version or date shown | Local file | BCMS use |
|---|---|---|---|---|
| IT-001 | IT Framework Memorandum for Supervised Institutions | Updated version April 2011 | 20190120_it_framework_memorandum_for_supervised_institutions.pdf | IT framework baseline, compliance, IT questionnaire, development and acquisition, outsourcing services |
| IT-002 | Policy Memorandum: Management of Computer Risks | Updated version April 2011 | 20190120_policy_memorandum_management_of_computer_risks.pdf | Computer risk taxonomy, control classes, preventive and containment controls, inspection and audit |
| IT-003 | Provisions and Guidelines for Information Security Management | Updated version April 2011 | 20190120_provisions_and_guidelines_for_information_security_management.pdf | Security framework, ongoing risk assessment, monitoring, incident response, privacy, training and audit |
| IT-004 | Provisions and Guidelines for Safe and Sound Electronic Banking | Updated version April 2011 | 20190120_provisions_and_guidelines_for_safe_and_sound_electronic_banking_updated_version_2011.pdf | E-banking risk management, internal control, cross-border e-banking, customer security and transparency |
| IT-005 | Provisions and Guidelines for Business Continuity Management | August 2021 | 20210827_provisions_and_guidelines_business_continuity_management.pdf | Context, oversight, business impact analysis, BCPs, training, testing, review and audit |
| IT-006 | Provisions and Guidelines for the Governance of Enterprise Information Technology | August 2021 | 20211018_provisions_and_guidelines_for_it_governance_2.pdf | IT governance framework, value contribution, risk management, capabilities, stakeholder communication and audit |
| IT-007 | Provisions and Guidelines for Information Technology Service Management | Version July 2014 | 20190120_provisions_and_guidelines_for_information_technology_service_management.pdf | Service management, support, assets, configuration, backup, third-party services, training and audit |
| IT-008 | Provisions and Guidelines for Software Testing | 2024-08-23 | 20240823_provisions_and_guidelines_for_software_testing.pdf | Test policy, test strategy, risk-based planning, test design, dedicated test environment, skills, security testing and assessment program |
Summary
This source consolidates the CBCS IT and technology guidance that underpins Bitkaya’s enterprise technology, security, continuity and testing expectations. Taken together, the documents establish a supervisory baseline for how an institution should govern IT, secure information assets, manage electronic banking risk, sustain operations, test software changes and maintain resilient services.
The guidance suite is intentionally grouped here because the documents share a common operating domain and are used together in BCMS to support enterprise IT governance, cyber and information security, service management, continuity planning and software-change assurance.
Relevant Provisions
Provision themes identified from the combined guidance:
- Board and senior-management oversight of IT and security
- IT governance frameworks, value delivery and stakeholder communication
- Information security risk assessment, monitoring and incident management
- Privacy protection and control of customer information
- IT service management, asset and configuration control, backup and restoration
- Management of third-party IT services and outsourced technology support
- Computer risk controls, preventive controls and audit oversight
- Electronic banking risk management and customer security
- Business continuity, RTO and RPO planning, training, testing and review
- Software testing policy, test strategy, planning, execution, security testing and ongoing assessment
Relationships
- Related policy: POL-ECM-001 Enterprise Compliance Manual, POL-IT-001 IT and Cybersecurity Manual, POL-COTS-001 Commercial Off-The Shelf Software Acceptance and Testing Manual, POL-BCM-001 Business Continuity Manual
- Related process: PRC-OTC-001 High-Level Overview of Principal OTC Service Delivery, PRC-RSA-001 Resilience Systems and Assurance, PRC-RSA-001 Resilience Systems and Assurance
- Related publication: PUB-ECM-001 Enterprise Compliance Manual
- Related systems: SYS-ECM-001 Compliance Framework Library, SYS-ECM-002 Compliance Reporting and Evidence Repository
- Requirement extraction: completed
Assurance
- CBCS PDFs reviewed: yes
- Title pages and section headings extracted: yes
- Consolidated-source decision recorded: yes
- Requirement-level extraction completed: yes
- Local PDFs stored in BCMS: no
- Applicability confirmed: review pending
History
- 2026-07-26: Created consolidated IT source object from eight CBCS guidance documents covering IT governance, information security, IT service management, electronic banking, computer risk management, business continuity and software testing.
- 2026-07-26: Extracted source requirements REQ-IT-001 through REQ-IT-008.