Bangladesh Bank

Cyber Security Unit   

Name & Designation Email Telephone Fax
Md. Mehedi HasanChief Information Security Officer880-2-9530624--

Overview:
Cyber Security Unit (CSU) was formed in Bangladesh Bank in July 2020.The activities of the said unit started from May 2020 with the joining of Md. Mehedi Hasan was designated by Chief Information Security Officer (CISO) as the head of CSU, Bangladesh Bank.
Functions of CSU:

  1. Design and implement BB’s information security infrastructure to monitor IT installations and systems for detection and prevention of unauthorized access and use; steering to completion of BB's ongoing cyber security strengthening program and conduct annual reviews thereof to identify, access and coordinate remediation of weaknesses in BB’s IT security systems.
  2. Take necessary steps in areas of Security Engineering (SE), Security Threat and Vulnerability Management (STVM), Information Security Operations Center (ISOC), Security Information and Event Management (SIEM), Financial Sector wide Critical Incident Response Team (CIRT) and Cyber Security Intelligence (CSI), putting in place adequate documented processes, procedures and internal technical controls in all these areas.
  3. Assess knowledge/skill enhancement needs for staff in the new CSU, set up appropriate training routines of cyber security capacity building with up-to-date understanding of emerging trends in information security technology.
  4. Ensure BB’s response-preparedness to IT security incidents through development and regular exercise of incidence response and procedures, forecast leadership skills in getting things done in inter-departmental/inter-agency team environments.
  5. Foster and facilitate a cyber security risk aware culture among all staffers in BB offices and departments and ensure effective, efficient and balanced protection of all BB information assets.
  6. Develop security standards for IT platform in conformance with BB’s IT architecture, risk profile and policy requirements.
  7. Interface with business units and IT stakeholders in identifying requirements and assess their applicability to BB's IT infrastructure.
  8. Identify efficiencies to improve the performance and responsiveness of BB’s security work programs.
  9. Review and offer suggestions on setting the technical requirements in procurements of IT equipments/consumables in conformance with BB’s information security architecture and risk profile.
  10. Design short-term and long-term security policy and implementation plan for BB.
  11. Take necessary measure to upgrade and maintain security infrastructure of BB according to the implementation plan.
  12. Assist in arrangement of regular security testing on the ICT infrastructure of BB, audit existing systems and provide comprehensive risk assessments.
  13. Ensure regular review of logs of user activities in order to recognize suspicious behavior.
  14. To design automatic (machine learning based) monitoring and financial fraud detection policy.
  15. Design monitoring plan of the implementation process of security policy by Banks and NBFI's of Bangladesh.
  16. Guide Banks and NBFI’s of Bangladesh to take appropriate preventive measures in case of any security threat/incident at any of the financial institute in Bangladesh or relevant organization abroad.
  17. Facilitate security awareness program for all employees of the bank at regular interval.
  18. Prepare a team for digital forensic investigation to investigate any incident.
  19. Assist to integrate IT systems for development with security policies and information protection strategies.
  20. Collaborate with key stakeholders to establish an IT security risk management program.
  21. Anticipate new security threats and stay-up-to-date with evolving infrastructures.