Analyzes information security and cybersecurity standards and regulations, and fosters a security culture in the use of new technologies.
Objective and functions
Analyze standards, current and pending regulations, guides, recommendations and manuals from internationally recognized organizations that serve as a reference to identify, monitor and prevent information security and cyber risks, and foster a security culture in the use of new technologies.
- 01Prepare a periodic report of relevant cybersecurity indicators.
- 02Compile statistics on cybersecurity events that serve as a basis for members’ decisions in managing their institutions’ risks.
- 03Promote new regulations or changes to existing ones to strengthen the legal framework and the control of information and cyber security.
- 04Promote best practices among members to mitigate this risk.
- 05Hold discussions with figures from the public and private sectors.
What technology and cyber risk is
Cybersecurity risk
Effect of uncertainty on information and technology. It translates into possible losses of confidentiality, integrity or availability that affect operations, assets, people and the economy.
SourceNIST, Glosario: cybersecurity risk (opens in a new tab)
Technology risk
Risk that failures, obsolescence, inadequate change management or dependence on providers in information systems interrupt or impair services. It is the link between operational risk and cybersecurity.
How it is measured and quantified
There are two complementary paths: operational indicators and financial quantification of risk.
Financial quantification (FAIR)
Risk = frequency of loss events × magnitude of lossThe FAIR model, maintained by The Open Group, expresses cyber risk in monetary terms, breaking frequency down into threat frequency and vulnerability.
Qualitative risk assessment
Probability and impact matrices by asset and scenario, following the information security risk management process of ISO/IEC 27005.
Maturity of the NIST CSF 2.0 framework
Self-assessment of the framework’s six functions (Govern, Identify, Protect, Detect, Respond and Recover) and of the implementation tiers.
Exposure indicators
Percentage of assets with critical patches up to date, age of open vulnerabilities, multifactor authentication coverage, results of phishing tests.
Response indicators
Mean time to detect and to contain, number and severity of incidents, and recovery time of critical services.
How it is managed
Coordination
Those who lead the committee. The coordination and co-coordination roles rotate once a year.
Coordination
Félix Rodríguez Paulino
Associate Vice President of Non-Financial Risks and Internal Control, Banco Promerica
Co-coordination
Freddy Pérez Estevez
Vice President of Information Security, Banco Promerica
Regulations and recommended readings
Standards and documents that the committee uses as the basis of its work.
- Cybersecurity and Information Security Regulation, Central Bank
- Decree 230-18, National Cybersecurity Strategy
- NIST, Cybersecurity Framework 2.0, 2024 (opens in a new tab)
- NIST, Glosario: cybersecurity risk (opens in a new tab)
- ISO/IEC 27000, Information security
- ISO/IEC 27005, Information security risk management
- ISO/IEC 27032, Cybersecurity management
Sign up for this committee
Members who wish to take part notify the Club’s Executive Committee, and this form is the channel. Regular members and representatives of sponsor members may take part. Not a member yet? Find out how to become one.
Connect with our networks