Skip to content

Latest commit

 

History

History
116 lines (79 loc) · 6.08 KB

File metadata and controls

116 lines (79 loc) · 6.08 KB

BACEN Resolution 4.658/2018 — Predecessor Cybersecurity Framework

Metadata

Field Detail
Jurisdiction Federative Republic of Brazil
Regulation Resolução No. 4.658 (April 26, 2018)
Enacted April 26, 2018
Effective May 6, 2019 (phased implementation)
Regulator Banco Central do Brasil (BCB / BACEN)
Status Superseded by Resolução BCB No. 4.893 (February 26, 2021)
Official Text bcb.gov.br

Overview

Resolution 4.658/2018 (Resolução No. 4.658) was the Banco Central do Brasil's first comprehensive cybersecurity regulation for financial institutions. Enacted in April 2018 and phased in through May 2019, it established the foundational framework for cybersecurity policy and cloud computing governance in Brazil's financial sector — a framework that Resolution 4.893/2021 later strengthened and expanded.

Understanding 4.658 remains relevant because:

  • Legacy contracts signed between 2018 and mid-2021 often reference it
  • Audit findings from that period cite its article numbers
  • Transition assessments compare old vs. new requirements
  • Some smaller credit unions (cooperativas) and payment institutions are still completing gap remediation from 4.658 to 4.893

What Resolution 4.658 Established

Cybersecurity Policy (Política de Segurança Cibernética)

The regulation required all BCB-supervised institutions to adopt a formal, Board-approved cybersecurity policy addressing:

  • Objectives and scope of the cybersecurity program
  • Information security procedures and controls
  • Roles and responsibilities
  • Incident response procedures
  • Employee training and awareness
  • Annual reporting to senior management

This was the first time BCB mandated board-level ownership of cybersecurity for all institution types — not just systemically important banks.

Cloud Computing Framework — Brazil's First

Resolution 4.658 introduced Brazil's first regulatory framework specifically governing cloud computing use in financial services:

Principle Detail
Cloud is permitted Institutions could use third-party cloud infrastructure for data processing and storage
Risk equivalence Controls applied to cloud-hosted data must be equivalent to on-premises controls
BCB audit rights Cloud providers must contractually grant BCB inspection rights over data and systems
Data location Data could be stored abroad if BCB access rights were preserved
Due diligence Institutions required to assess cloud providers before engagement

This framework was groundbreaking for the region — it gave regulated institutions a clear path to cloud adoption while establishing the audit-rights principle that 4.893 later reinforced.

Outsourcing / Third-Party Risk

4.658 established that institutions must assess and manage risk from material service providers (prestadores de serviços relevantes), including:

  • Data processing companies
  • Core banking system vendors
  • Cloud infrastructure providers
  • IT outsourcing firms with privileged access

Contracts with these providers were required to include security standards, incident notification obligations, and audit rights.


Key Gaps That Led to 4.893

Weakness in 4.658 How 4.893 Addressed It
No specific incident notification deadline 72-hour hard deadline to BCB
Cloud rules were principles-based Specific controls, exit plans, concentration risk
Third-party risk was high-level Detailed due diligence, subcontractor visibility
No structured board reporting template More prescriptive annual report content
Concentration risk not explicitly addressed Explicit single-provider dependency assessment

Why 4.658 Still Appears in Contracts and Audits

Legacy Contract References

Vendor contracts and outsourcing agreements executed between 2018 and mid-2021 often contain clauses like:

"The parties agree to comply with the requirements of Banco Central Resolution 4.658/2018 and any successor regulations."

These contracts are typically valid until renegotiated or renewed. During audits, examiners may review whether the institution's arrangements with vendors effectively meet 4.893, even if the contract text references 4.658. The key question is whether substantive compliance (72h notification, audit rights, exit plans) has been achieved — not whether the contract number has been updated.

Audit Trail and Evidence

Any security audits, penetration test reports, or board presentations prepared under 4.658 form part of the institution's ongoing compliance history. BACEN examiners reviewing the transition to 4.893 will look at this history as evidence of the institution's cybersecurity maturity trajectory.

Transition Timeline

Date Event
April 26, 2018 Resolution 4.658 enacted
May 6, 2019 Full implementation deadline for all institutions
February 26, 2021 Resolution 4.893 enacted, superseding 4.658
July 1, 2021 Resolution 4.893 effective date

Institutions had a 5-month window (February–June 2021) to assess gaps between their 4.658-compliant programs and the new 4.893 requirements.


Key Takeaways for Enterprise Buyers

  1. 4.658 is superseded — no institution should cite it as their current compliance baseline; 4.893 is the operative standard
  2. Legacy contract language is common — when reviewing vendor agreements, look for substantive compliance with 4.893 requirements even if the contract cites 4.658
  3. The cloud permissions it established remain in 4.893 — BCB has consistently supported cloud adoption, with audit rights as the key condition
  4. Security products sold under 4.658-era contracts may need formal re-assessment under 4.893's more stringent third-party risk requirements
  5. Audit history matters — your 4.658-era documentation (board reports, pen test results) is still relevant evidence of your cybersecurity program maturity