Compliance · Israel
Proper Conduct of Banking Business Directive 364 Supersedes Directives 357, 361 & 363

נב"ת — Bank of Israel Cyber & IT Risk Directive

Plain-English definition

נב"ת (Nihul Bankai Takin, "Proper Conduct of Banking Business") is the Bank of Israel's directive series for regulated banking entities. Directive 364, published November 2024, consolidates the former Directive 357 (IT management), Directive 361 (cyber defense) and Directive 363 (data protection) into a single, technology-neutral risk-management framework. Banks and credit card companies must transition by the earlier of their own adoption date or May 18, 2026.

Directive 361 is the name most practitioners still search for. It is not a separate current obligation, it has been folded into 364.

Who needs it

Banking corporations and credit card companies regulated by the Bank of Israel's Banking Supervision Department.

Key requirements

Board and management governance over cyber risk, a risk-assessment framework covering internal systems and third-party/outsourced providers, continuous monitoring and threat detection, incident response and resilience planning, periodic drills, and organization-wide staff training.

Cyber implications

Third-party and vendor remote access to critical systems must use strong, multi-factor authentication. The framework is deliberately technology-neutral, so evidence of a working risk process matters more than any specific tool.

Assessment methodology

Gap assessment against Directive 364's consolidated requirements, third-party/vendor risk review, incident-response readiness test, and a governance review of board-level cyber oversight.

Implementation phases

01
Assess

Map current controls against Directive 364, including the former 357/361/363 scope.

02
Remediate

Close governance, vendor-risk and monitoring gaps ahead of the transition deadline.

03
Evidence

Document board oversight, risk assessments and drill results in an audit-ready form.

Evidence & documentation requirements

Board and management minutes showing active cyber-risk oversight, asset and third-party risk assessments, incident-response logs, vendor due-diligence records, and periodic drill reports, all reviewable by the Banking Supervision Department.

Common mistakes

Treating נב"ת as an IT-only policy instead of a board-level governance obligation; assuming legacy Directive 361 controls alone satisfy 364's broader consolidated scope; and under-scoping third-party and vendor remote-access risk.

Expert review

Nitzan Levi
Nitzan Levi
Co-Founder, Cybecs · Co-Founder, RedRok · Executive Director, Privacy & GRC · CISM, CISSP, CDPSE, CCSK, CSA

FAQ

Is Directive 364 the same thing as נב"ת 361?
No. Directive 364, published November 2024, supersedes and consolidates the former Directives 357, 361 and 363 into one integrated IT, cyber and data-protection framework. Institutions must transition by the earlier of their own adoption date or May 18, 2026.
Does this apply to fintechs that aren't banks?
Directly, it applies to banking corporations and credit card companies. Fintechs that partner with or provide services to a regulated bank are commonly captured indirectly, through that bank's own third-party risk-management obligations under the directive.

Request a Gap Assessment

See exactly where your controls stand against Directive 364's consolidated requirements before your transition deadline.

Request a Gap Assessment →