BANKING AND FINANCE LAW IN CAMEROON

According to COBAC regulation R-2008/01 requiring credit institutions to prepare a business continuity plan in Cameroon, the credit institutions shall define the organization and the reaction mode capable to ensure the operational nature of the technical backup solution in the event of activation of the business continuity plan.

In particular, they shall define the roles, responsibilities and authorities in charge of implementing the IT back-up plan and shall determine the solutions for replacing or substituting staff, with a definition and planning of their tasks.

A test of the technical solutions and of the IT recovery plan is carried out to allow their validation from a technical and organizational point of view and, thus, to verify their ability to meet the defined needs and to assess the recovery times.

If the technical solution is not validated, all possible information must be gathered in order to implement corrective measures to make the backup solution operational.

The scope, the extent, the objectives and the conditions of the test must be defined beforehand. The main conclusions of the test must be communicated to the interested parties and the corrective actions resulting from the findings must be implemented.

CRITICAL ASPECTS OF THE COMPUTER BACKUP PLAN FOR A CREDIT INSTITUTION IN CAMEROON

  • Critical Assets and SLAs
  • Assets to back up: This has to do with core banking and transaction databases, PII (Personally Identifiable Information), audit trails, and SaaS application data.
  • RTO (Recovery Time Objective): This has to do with core transaction processing systems.
  • RPO (Recovery Point Objective): This has to do with maintaining near-zero data loss using Continuous Data Protection (CDP).
  • Implement the 3-2-1-1-0 Storage Rule
  • 3 Copies: This is a practice to keep the production data plus two independent copies.
  • 2 Media Types: This is a practice to combine fast local storage such as local servers with scalable enterprise cloud storage like Microsoft Azure or AWS Backup.
  • 1 Off-site Copy: This is a practice to utilize geographically separated, secure cloud-based BaaS (Backup-as-a-Service) to protect against local disasters.
  • 1 Offline/Immutable Copy: This is a method to prevent ransomware modification by employing air-gapped or WORM (Write Once, Read Many) storage systems.
  • 0 Errors: This is a practice to run automated integrity checks to guarantee system usability and ensure stability.
  • Compliance and Security
  • Encryption: This is a practice to implement strong end-to-end encryption for data in transit and at rest.
  • Access Control: This is to enforce Multi-Factor Authentication (MFA) and strictly restrict access to the backup environment by the
  • Compliance: Ensure your retention and archiving schedule adheres strictly to financial data guidelines.

4. Continuous Testing and MaintenanceRun automated recovery and restore drills monthly.Audit data locations and backup performance metrics regularly to eliminate single points of failure.