LGPD (Lei Geral de Proteção de Dados) + BCB Resolution 4893/2021
Brazil's combined data protection and financial cybersecurity framework. LGPD (Law 13,709/2018) establishes comprehensive data protection principles, data subject rights, international transfer rules, and ANPD oversight. BCB Resolution 4893/2021 mandates cybersecurity policy, incident response and reporting, cloud governance, board accountability, and annual cybersecurity reporting for financial institutions regulated by the Banco Central do Brasil. Includes PIX instant payment security and Open Finance Brasil API requirements.
AC (10) AT (5) AU (10) CA (8) CM (5) CP (6) IA (4) IR (9) MA (1) MP (6) PE (3) PL (7) PM (11) PS (9) RA (10) SA (4) SC (8) SI (9)
AC Access Control
| Control | Name | LGPD + BCB 4893 References |
|---|---|---|
| AC-01 | Policy and Procedures | BCB.Art.2BCB.Art.3LGPD.Art.46LGPD.Art.50 |
| AC-02 | Account Management | BCB.Art.3BCB.PIXLGPD.Art.46 |
| AC-03 | Access Enforcement | BCB.Art.3BCB.OpenFinanceBCB.PIXLGPD.Art.11LGPD.Art.46 |
| AC-04 | Information Flow Enforcement | BCB.Art.3BCB.Art.13BCB.Art.14BCB.OpenFinanceBCB.PIXLGPD.Art.23-26LGPD.Art.33-36LGPD.Art.46 |
| AC-05 | Separation of Duties | BCB.Art.3LGPD.Art.46 |
| AC-06 | Least Privilege | BCB.Art.3LGPD.Art.6LGPD.Art.46 |
| AC-08 | System Use Notification | LGPD.Art.9 |
| AC-16 | Security and Privacy Attributes | LGPD.Art.11 |
| AC-17 | Remote Access | BCB.PIXLGPD.Art.33-36 |
| AC-20 | Use of External Systems | BCB.Art.11 |
AT Awareness and Training
| Control | Name | LGPD + BCB 4893 References |
|---|---|---|
| AT-01 | Policy and Procedures | BCB.Art.2BCB.Art.4LGPD.Art.47LGPD.Art.50 |
| AT-02 | Literacy Training and Awareness | BCB.Art.4LGPD.Art.47LGPD.Art.50 |
| AT-03 | Role-based Training | BCB.Art.4LGPD.Art.47 |
| AT-05 | Contacts with Security Groups and Associations | BCB.Art.4 |
| AT-06 | Training Feedback | BCB.Art.4LGPD.Art.50 |
AU Audit and Accountability
| Control | Name | LGPD + BCB 4893 References |
|---|---|---|
| AU-01 | Policy and Procedures | BCB.Art.2BCB.Art.18BCB.Art.20LGPD.Art.6LGPD.Art.42-45LGPD.Art.46 |
| AU-02 | Event Logging | BCB.Art.6BCB.Art.20LGPD.Art.6LGPD.Art.8LGPD.Art.42-45 |
| AU-03 | Content of Audit Records | BCB.Art.20LGPD.Art.8LGPD.Art.42-45 |
| AU-04 | Audit Log Storage Capacity | BCB.Art.9BCB.Art.20 |
| AU-06 | Audit Record Review, Analysis, and Reporting | BCB.Art.6BCB.Art.8LGPD.Art.48 |
| AU-07 | Audit Record Reduction and Report Generation | BCB.Art.20 |
| AU-09 | Protection of Audit Information | BCB.Art.3BCB.Art.9BCB.Art.15BCB.Art.20LGPD.Art.46 |
| AU-10 | Non-repudiation | LGPD.Art.42-45 |
| AU-11 | Audit Record Retention | BCB.Art.9BCB.Art.20LGPD.Art.15-16 |
| AU-16 | Cross-organizational Audit Logging | BCB.Art.15 |
CA Security Assessment and Authorization
| Control | Name | LGPD + BCB 4893 References |
|---|---|---|
| CA-01 | Policy and Procedures | BCB.Art.2LGPD.Art.46LGPD.Art.50 |
| CA-02 | Control Assessments | BCB.Art.10BCB.Art.18BCB.Art.19LGPD.Art.37-38LGPD.Art.50 |
| CA-03 | Information Exchange | BCB.Art.11 |
| CA-04 | Security Certification | BCB.Art.10BCB.Art.19 |
| CA-05 | Plan of Action and Milestones | BCB.Art.18BCB.Art.19LGPD.Art.50 |
| CA-07 | Continuous Monitoring | BCB.Art.6BCB.Art.10BCB.Art.19LGPD.Art.50 |
| CA-08 | Penetration Testing | BCB.Art.10 |
| CA-09 | Internal System Connections | BCB.Art.11 |
CM Configuration Management
CP Contingency Planning
IA Identification and Authentication
| Control | Name | LGPD + BCB 4893 References |
|---|---|---|
| IA-01 | Policy and Procedures | BCB.Art.2BCB.Art.3LGPD.Art.46 |
| IA-02 | Identification and Authentication (Organizational Users) | BCB.Art.3BCB.OpenFinanceBCB.PIXLGPD.Art.46 |
| IA-05 | Authenticator Management | BCB.Art.3BCB.OpenFinanceBCB.PIXLGPD.Art.46 |
| IA-08 | Identification and Authentication (Non-organizational Users) | BCB.OpenFinanceBCB.PIX |
IR Incident Response
| Control | Name | LGPD + BCB 4893 References |
|---|---|---|
| IR-01 | Policy and Procedures | BCB.Art.2BCB.Art.5LGPD.Art.48 |
| IR-02 | Incident Response Training | BCB.Art.5 |
| IR-03 | Incident Response Testing | BCB.Art.5 |
| IR-04 | Incident Handling | BCB.Art.5BCB.Art.5-SuppBCB.Art.6BCB.Art.7LGPD.Art.48LGPD.Art.49 |
| IR-05 | Incident Monitoring | BCB.Art.5BCB.Art.5-SuppBCB.Art.7LGPD.Art.48 |
| IR-06 | Incident Reporting | BCB.Art.5BCB.Art.8LGPD.Art.48LGPD.Art.49 |
| IR-07 | Incident Response Assistance | BCB.Art.5BCB.Art.7LGPD.Art.48 |
| IR-08 | Incident Response Plan | BCB.Art.5BCB.Art.5-SuppBCB.Art.8LGPD.Art.48 |
| IR-09 | Information Spillage Response | BCB.Art.7LGPD.Art.48 |
MA Maintenance
| Control | Name | LGPD + BCB 4893 References |
|---|---|---|
| MA-01 | Policy and Procedures | BCB.Art.2 |
MP Media Protection
PE Physical and Environmental Protection
PL Planning
| Control | Name | LGPD + BCB 4893 References |
|---|---|---|
| PL-01 | Policy and Procedures | BCB.Art.2LGPD.Art.50LGPD.BCB.Integration |
| PL-02 | System Security and Privacy Plans | LGPD.Art.37-38LGPD.Art.50LGPD.BCB.Integration |
| PL-04 | Rules of Behavior | BCB.Art.4LGPD.Art.47LGPD.Art.50 |
| PL-05 | Privacy Impact Assessment | LGPD.Art.37-38 |
| PL-09 | Central Management | BCB.Art.2BCB.Art.17LGPD.Art.50LGPD.BCB.Integration |
| PL-10 | Baseline Selection | BCB.Art.3-Supp |
| PL-11 | Baseline Tailoring | BCB.Art.3-Supp |
PM Program Management
| Control | Name | LGPD + BCB 4893 References |
|---|---|---|
| PM-01 | Information Security Program Plan | BCB.Art.2BCB.Art.17LGPD.Art.50LGPD.BCB.Integration |
| PM-02 | Information Security Program Leadership Role | BCB.Art.17BCB.Art.17-SuppLGPD.Art.41 |
| PM-04 | Plan of Action and Milestones Process | BCB.Art.5BCB.Art.19LGPD.Art.49 |
| PM-05 | System Inventory | BCB.Art.20 |
| PM-06 | Measures of Performance | BCB.Art.18BCB.Art.19 |
| PM-07 | Enterprise Architecture | BCB.Art.3-Supp |
| PM-08 | Critical Infrastructure Plan | BCB.Art.11BCB.Art.16 |
| PM-09 | Risk Management Strategy | BCB.Art.2BCB.Art.3-SuppBCB.Art.17LGPD.Art.50LGPD.BCB.Integration |
| PM-11 | Mission and Business Process Definition | BCB.Art.3-Supp |
| PM-13 | Security and Privacy Workforce | BCB.Art.4 |
| PM-14 | Testing, Training, and Monitoring | BCB.Art.4BCB.Art.10BCB.Art.19LGPD.Art.50 |
PS Personnel Security
| Control | Name | LGPD + BCB 4893 References |
|---|---|---|
| PS-01 | Policy and Procedures | BCB.Art.2LGPD.Art.47 |
| PS-02 | Position Risk Designation | LGPD.Art.47 |
| PS-03 | Personnel Screening | LGPD.Art.47 |
| PS-04 | Personnel Termination | LGPD.Art.47 |
| PS-05 | Personnel Transfer | LGPD.Art.47 |
| PS-06 | Access Agreements | LGPD.Art.47 |
| PS-07 | External Personnel Security | LGPD.Art.47 |
| PS-08 | Personnel Sanctions | LGPD.Art.47 |
| PS-09 | Position Descriptions | BCB.Art.17BCB.Art.17-SuppLGPD.Art.41LGPD.Art.47 |
RA Risk Assessment
| Control | Name | LGPD + BCB 4893 References |
|---|---|---|
| RA-01 | Policy and Procedures | BCB.Art.2BCB.Art.3-SuppLGPD.Art.37-38LGPD.Art.50LGPD.BCB.Integration |
| RA-02 | Security Categorization | BCB.Art.5-Supp |
| RA-03 | Risk Assessment | BCB.Art.3-SuppBCB.Art.12BCB.Art.18LGPD.Art.10LGPD.Art.37-38LGPD.BCB.Integration |
| RA-04 | Risk Assessment Update | BCB.Art.18BCB.Art.19 |
| RA-05 | Vulnerability Monitoring and Scanning | BCB.Art.6BCB.Art.10BCB.Art.19 |
| RA-06 | Technical Surveillance Countermeasures Survey | BCB.Art.10 |
| RA-07 | Risk Response | BCB.Art.3-Supp |
| RA-08 | Privacy Impact Assessments | LGPD.Art.10LGPD.Art.37-38 |
| RA-09 | Criticality Analysis | BCB.Art.3-SuppBCB.Art.5-SuppBCB.Art.12 |
| RA-10 | Threat Hunting | BCB.Art.6 |
SA System and Services Acquisition
| Control | Name | LGPD + BCB 4893 References |
|---|---|---|
| SA-01 | Policy and Procedures | BCB.Art.2 |
| SA-04 | Acquisition Process | BCB.Art.11BCB.Art.11-SuppBCB.Art.12BCB.Art.16 |
| SA-09 | External System Services | BCB.Art.11BCB.Art.11-SuppBCB.Art.12BCB.Art.13BCB.Art.14BCB.Art.15BCB.Art.16BCB.OpenFinanceLGPD.Art.23-26LGPD.Art.33-36 |
| SA-11 | Developer Testing and Evaluation | BCB.Art.10 |
SC System and Communications Protection
| Control | Name | LGPD + BCB 4893 References |
|---|---|---|
| SC-01 | Policy and Procedures | BCB.Art.2 |
| SC-07 | Boundary Protection | BCB.Art.3BCB.Art.13BCB.OpenFinanceBCB.PIXLGPD.Art.46 |
| SC-08 | Transmission Confidentiality and Integrity | BCB.Art.3BCB.Art.14BCB.OpenFinanceBCB.PIXLGPD.Art.33-36LGPD.Art.46 |
| SC-12 | Cryptographic Key Establishment and Management | BCB.Art.3BCB.PIXLGPD.Art.46 |
| SC-13 | Cryptographic Protection | BCB.Art.3BCB.OpenFinanceBCB.PIXLGPD.Art.46 |
| SC-23 | Session Authenticity | BCB.OpenFinanceBCB.PIX |
| SC-24 | Fail in Known State | BCB.Art.7 |
| SC-28 | Protection of Information at Rest | BCB.Art.3LGPD.Art.11LGPD.Art.46 |
SI System and Information Integrity
| Control | Name | LGPD + BCB 4893 References |
|---|---|---|
| SI-01 | Policy and Procedures | BCB.Art.2BCB.Art.3LGPD.Art.46 |
| SI-02 | Flaw Remediation | BCB.Art.3BCB.Art.6LGPD.Art.46 |
| SI-03 | Malicious Code Protection | BCB.Art.3LGPD.Art.46 |
| SI-04 | System Monitoring | BCB.Art.3BCB.Art.6BCB.Art.7BCB.PIXLGPD.Art.46 |
| SI-05 | Security Alerts, Advisories, and Directives | BCB.Art.6 |
| SI-07 | Software, Firmware, and Information Integrity | BCB.Art.3LGPD.Art.46 |
| SI-10 | Information Input Validation | BCB.PIX |
| SI-12 | Information Management and Retention | BCB.Art.9BCB.Art.20LGPD.Art.15-16 |
| SI-18 | Personally Identifiable Information Quality Operations | LGPD.Art.6LGPD.Art.17-18 |