Audit for MNB cloud recommendation

In April 2019 the National Bank of Hungary (Magyar Nemzeti Bank – MNB) published on its website Recommendation No. 4/2019 (of 1st April) of the MNB on the usage of community and public cloud computing services, with the objective to provide practical guidance to entities in the financial intermediary system for managing the risks arising from the use of community and public cloud computing services, and for the uniform interpretation of the relevant national and EU legislation and other regulatory instruments. The Recommendation shall be applied from 1st May 2019.*

HUNGUARD Kft. offers an IT audit to ensure compliance with the provisions of the Recommendation to financial companies that have outsourced or plan to outsource any system used for serving their services or activities to a public, private, or hybrid cloud. According to the Recommendation of the MNB, such cloud services include Infrastructure as a Service provided by external or in-house service providers, such as e.g. Microsoft Azure, Google Cloud Platform, cloud services provided within the company group, but e.g. Microsoft Office 365, or Google G Suite as well.

The purpose of the audit is to determine whether the preparation for the implementation of outsourcing to cloud service providers, the performance of the implementation, and the preparation for the exit complies with the requirements set forth in the Recommendation of the MNB.

During the audit, we test the existence of a system of contracts and IT security controls applied by the organization, and the efficiency, proper application of the measures, tools used for their enforcement. The result of the test is recorded in an audit report.

If Your organization requires certification, we can test a certain subfield and issue a certificate of the integrity of the IT system components operated by the organization.

Taking into consideration the structure of the Recommendation, we perform the test in the course of our work according to the following main aspects:

  1. Testing of information security
  2. Testing of data protection
  3. Testing of legal compliance
  4. Testing of exit

If You need more information on our audit service, please contact our colleagues via e-mail at ertekesites@hunguard.hu, giving your contact details or your concrete questions, and we will call You back.


*Source: MNB website: https://www.mnb.hu/felugyelet/felugyeleti-keretrendszer/felugyeleti-hirek/hirek-ujdonsagok/megjelent-az-uj-felho-ajanlas


related link: https://www.mnb.hu/letoltes/4-2019-cloud-bg.pdf