Content
Services
Industries
Talk to an expert

SOC for financial institutions: what to monitor under CMN 5,274

· 7 min read · Network Secure

CMN Resolution No. 5,274/2025 replaced principles with verifiable controls. For whoever runs a financial institution's SOC, the consequence is direct: many of the 14 minimum controls only exist in practice if someone is watching events continuously and can later prove they did.

The controls that depend on continuous monitoring

Resolution 5,274 amended article 3 of CMN Resolution No. 4,893/2021 and spelled out minimum requirements for several items. Some of them are essentially SOC work:

  • Intrusion prevention and detection. Without monitoring and triage, detection is just an alert nobody reads.
  • Traceability. Paragraph 7 requires end-to-end audit trails of processing, with logs that make it possible to identify failures or atypical behaviour and support analysis, a retention period defined by type of processing, and secure retention of the trails.
  • Network protection. Paragraph 11 calls for monitoring connections with external environments and for processes to handle atypical events in production, citing as examples the establishment of VPNs and privileged access attempts, especially at night and on non-business days.
  • Digital certificate management. Paragraph 12 includes monitoring the use of certificates and digital signatures, tied to the traceability mechanisms.
  • Cyber intelligence. Item XIV includes monitoring information of interest to the institution on the internet, the deep web, the dark web and private messaging groups.

Traceability is not just keeping logs. The rule speaks of trails that make it possible to identify atypical behaviour and support analysis. Logs that are collected and never correlated meet the letter of retention, but not the purpose of the control.

Credentials and digital certificates

For communication over the RSFN (the National Financial System Network), the new article 3-A requires monitoring the use of credentials and digital certificates, especially those used in the Instant Payment System (SPI), and forbids service providers from accessing the private keys used to sign messages. For the SOC, this translates into concrete signals:

  • Unusual use. A certificate or service credential used from a different server, at a different time or in a different volume than usual.
  • Access to private keys. Any read or export in the vault or HSM outside the defined process, and any access attempt by a third-party account, should become an alert.
  • Revocation and validity. Paragraph 12 calls for timely validation of revoked certificates; alerts on revoked certificates in use or certificates close to expiry prevent incidents and outages.

Pix, RSFN and STR environments

Article 3-A requires multi-factor authentication for administrative access to the Pix and STR (Reserve Transfer System) environments and physical and logical isolation of those environments, with a dedicated instance when they run on contracted cloud. Isolation is an architecture control, but its effectiveness is proven through monitoring: traffic that crosses the boundary of an isolated environment without being expected should be treated as a potential incident, not as noise.

The rule also requires end-to-end validation of transaction integrity before messages are signed. Failures in that validation are security events: the SOC should receive them, because they may indicate tampering and not just a processing error. And for participants in Financial Market Systems, the same article calls for fraud prevention, detection and response controls.

Detection use cases

A use case is only useful if it has a data source, logic, an owner and a defined action. Four families cover much of a financial institution's risk:

  • Transaction fraud. Spikes in transactions per account, registration of keys or payees followed by an immediate transfer, limit changes outside the normal flow. This requires integration with the anti-fraud team: the SOC sees the infrastructure, anti-fraud sees the business.
  • Compromised account. Logins from a location inconsistent with the previous one, repeated MFA prompts, a new device followed by a password or e-mail change, administrative sessions outside business hours.
  • API abuse. With Open Finance and integrations, the API is the front door. The OWASP API Security Top 10 (2023 edition) lists risks such as broken object level authorization and unrestricted resource consumption; in practice, identifier enumeration, anomalous volume per client and calls to endpoints outside the contract.
  • Lateral movement. Administrative credentials used across a sequence of hosts, unusual remote access tools, new VPNs at night. It is exactly the example paragraph 11 gives.

Mapping these cases to MITRE ATT&CK tactics and techniques helps show coverage and gaps, as we discussed in SOC maturity.

The evidence the SOC should produce

Article 21 of Resolution 4,893 requires monitoring and control mechanisms with processes, tests and audit trails, metrics and indicators, and correction of deficiencies. Article 23 requires the data and records of those mechanisms to be kept available to the Central Bank for five years. The SOC is one of the main sources of this material:

  • Log source inventory mapped to each minimum control, showing what is and is not covered.
  • Retention policy by type of processing, as paragraph 7 requires, and proof that the trails are protected against tampering.
  • Use case catalogue listing the regulatory requirement each one supports.
  • Incident register with cause, impact and control of effects (article 3, IV), including incidents reported by service providers.
  • Indicators such as mean time to detect and to respond, and their trend.
  • Input for the annual report under article 8, which must cover the relevant incidents of the period.

There is also the timely notification to the Central Bank of relevant incidents that amount to a crisis (article 20). The SOC does not decide what counts as a crisis, but it must deliver the facts fast enough for the decision to be made in time, as defined in the incident response plan.

Outsourced SOC from a third-party risk perspective

Hiring a SOC does not transfer responsibility, as we showed in the guide on third-party risk and CMN 4,893. An external SOC receives and stores the institution's logs; it is worth assessing with compliance and legal whether the contract falls under the rules for contracting data processing and storage, and treating it with rigour proportional to its relevance. Questions the contract should answer:

  • Where logs are processed and stored, including whether outside Brazil.
  • How the institution accesses and exports its data, and what happens to it when the contract ends.
  • Which certifications and audit reports the provider presents, and how long they are valid.
  • How the provider reports incidents and subcontracting, because the institution's incident register must include information received from third parties (article 3, paragraph 4).
  • Who accesses what. The SOC monitors certificate use, but should not have access to the private signing keys.

At Network Secure. Network Secure's SOC is ISO/IEC 27001:2022 certified. In the FitBank case, the service runs 24×7 under the N1 management model: the SOC team filters events and sends what matters to the client's IT team, which reviews and takes action. According to Gustavo Ramos, FitBank's head of infrastructure and security, there has been a significant reduction in the number of incidents since the rollout. See financial sector and SOC and MDR.

Frequently asked questions

Does CMN Resolution 5,274 require a SOC?

Not by that name. It requires intrusion detection, traceability, and monitoring of connections, atypical events and the use of credentials and certificates. In practice, doing that continuously requires a monitoring operation, in-house or outsourced.

How long must logs be kept?

The resolution requires the retention period to be defined according to the type of processing and retention to be secure; it does not set a single period for logs. Records of the monitoring and control mechanisms under article 21 must be kept available to the Central Bank for five years.

Do payment institutions follow the same rule?

Payment institutions, brokers and dealers follow BCB Resolution No. 538/2025, which amended BCB Resolution No. 85/2021. Check the text that applies to your institution.

Sources consulted: CMN Resolution No. 5,274 of 18 December 2025, and the consolidated text of CMN Resolution No. 4,893 of 26 February 2021 (articles 3, 3-A, 8, 20, 21 and 23), on the Central Bank of Brazil website; BCB Resolution No. 538/2025; OWASP API Security Top 10 (2023); MITRE ATT&CK; NIST SP 800-61 Rev. 3. This article is educational and does not constitute legal advice; refer to the official text of the rules on the Central Bank website.

Official references

Read next