GR-12.2.4

The tests referred to in Paragraph GR-12.2.3 must be conducted each year in June and December by licensees required to perform the tests twice a year and in June for licensees required to perform the tests at least once a year. Reports on penetration testing must be submitted to CBB before 30th September for the tests as at 30th June and 31st March for the tests as at 31st December. The penetration testing reports must include the vulnerabilities identified and a full list of ‘passed’ tests and ‘failed’ tests together with the steps taken to mitigate the risks identified.

Amended: January 2022
Added: July 2021