i-Prot

Frameworks · BCRA (Com. “A” 7724)

BCRA: meet the Central Bank’s cybersecurity requirements.

We prepare and support financial institutions to comply with the BCRA regulations (Com. “A” 7724) — with controls, evidence and reporting ready.

diagram · frameworks · bcra (com. “a” 7724)

Who it applies to

The BCRA regulations apply to financial institutions and providers of the Argentine financial system subject to its cybersecurity communications.

What the framework requires

The BCRA regulations (Com. “A” 7724) require a cybersecurity governance and risk-management approach, with controls, incident management and reporting to the regulator.

Governance

Roles, responsibilities and oversight.

Risk management

Identification and treatment of cyber risks.

Controls and incidents

Controls and incident management.

Regulator reporting

Information and evidence for the BCRA.

Risks of not acting

  • Observations and sanctions from the regulator for non-compliance.
  • Managing cybersecurity without a formal governance framework.
  • Being unable to report incidents in time and form.
  • A lack of evidence in the face of an inspection.

The i-Prot proposal

We align governance, risk management, controls and incident reporting with the BCRA regulations, leaving the evidence ready for the regulator. Integrated into the CGF cycle.

How we work with this framework

Regulatory assessment

Gaps against Com. “A” 7724.

Governance and risk

Roles and cybersecurity risk management.

Controls

Controls and incident management.

Reporting

Regulator reporting processes.

Upkeep

Evidence and indicators over time.

Deliverables

  • Gap analysis
  • Implementation plan
  • Controls matrix
  • System documentation
  • Evidence
  • Internal audit
  • Management review
  • Roadmap

How it connects with CGF

CGF uses the BCRA regulations as a source of requirements. This framework mainly covers the Assess, Design, Operate & measure, and Improve stages of the cycle.

See the CGF methodology →

Complyze and the BCRA

Complyze consolidates risks, controls, incidents and evidence, and makes reporting to the BCRA with data easier.

Frequently asked questions

Do you need to comply with the BCRA?

Tell us your institution and its scope, and we’ll define the regulatory approach.

By submitting you accept our privacy policy.

By submitting you accept the privacy policy and the processing of your data in order to be contacted.