Featured Product

    ECB Publishes Services Procurement Guidelines for TIBER-EU Tests

    August 07, 2018

    ECB published the Services Procurement Guidelines, which are referred to in, and are an integral part of, the Threat Intelligence-Based Ethical Red Teaming (TIBER-EU) framework. The guidelines set out in detail the different elements of TIBER-EU procurement. TIBER-EU framework enables European and national authorities to work with financial infrastructures and institutions to put in place a program to test and improve their resilience against sophisticated cyber attacks. Due to the sensitive nature of TIBER-EU tests, entities need to carefully select threat intelligence and red teaming providers that can provide an appropriate level of professional expertise and support for conducting the test.

    The first part of the document sets out the requirements and standards that must be met by threat intelligence providers to deliver recognized TIBER-EU tests and offers guiding principles and selection criteria for entities, as they look to procure services from prospective providers. Then, the document sets out the requirements and standards that must be met by red teaming providers to deliver recognized TIBER-EU tests and offer guiding principles and selection criteria for entities, as they look to procure services from prospective providers. Next, it provides guidance to authorities that are looking to implement TIBER-EU at the national and European levels, with regard to procurement. Annex 1 provides a list of certifications that staff members and providers may be, depending on the case, required to possess. Annexes 2-5 provide questions that entities could use when considering prospective providers and agreement checklists to assist the procurement functions during their procurement process.

    The guidelines are directed at authorities responsible for the adoption, implementation, and management of the TIBER-EU Framework at national and European levels; entities looking to undertake TIBER-EU tests; organizations interested in providing cyber threat intelligence services under TIBER-EU; organizations interested in providing red team testing services under TIBER-EU; and accreditation and certification providers. As the TIBER-EU Framework is implemented across EU, the TIBER-EU Knowledge Center (TKC) will monitor the evolution of the threat intelligence and red team testing market and update the requirements, if necessary. TKC will undertake this task by closely liaising with the authorities that adopt the TIBER-EU Framework, the entities that undertake the tests, and the threat intelligence/red teaming providers that deliver the tests.

     

    Related Link: Guidelines (PDF)

    Keywords: Europe, EU, Banking, Insurance, Securities, PMI, Cyber Risk, TIBER-EU, Cyber Resilience, Procurement Services Guidelines, ECB

    Related Articles
    News

    APRA Announces Deferral of Capital Reform Implementation

    APRA announced that it is deferring the scheduled implementation of Basel III reforms in Australia by one year.

    March 30, 2020 WebPage Regulatory News
    News

    IFRS Publishes Statement on Its Work During the COVID-19 Crisis

    IFRS, in its statement, emphasized that it shares global concerns about the impact of COVID–19 and is supporting its stakeholders by reconsidering timelines of its meetings and publications, providing information on the application of IFRS 9 on financial instruments, and offering calendar updates on ongoing activities.

    March 27, 2020 WebPage Regulatory News
    News

    US Agencies Announce Changes to SA-CCR and CECL Rules Due to COVID-19

    In light of the recent disruptions in economic conditions due to the COVID-19 outbreak, US Agencies (FDIC, FED, and OCC) announced two actions to allow banking organizations to continue lending to households and businesses.

    March 27, 2020 WebPage Regulatory News
    News

    IAIS Adjusts Work Program to Address Impact of COVID-19 on Insurers

    Considering the impact of COVID-19 outbreak, IAIS announced initial adjustments to its work program to provide operational relief to its member supervisors, insurers, and other stakeholders.

    March 27, 2020 WebPage Regulatory News
    News

    OSFI Announces Regulatory Adjustments to Support COVID-19 Efforts

    OSFI published three targeted industry letters that announce a series of regulatory adjustments to support the financial and operational resilience of federally regulated banks, insurers, and private pension plans in the light of COVID-19.

    March 27, 2020 WebPage Regulatory News
    News

    UK Regulators Announce Measures to Address Impact of COVID-19

    UK Regulatory Authorities published statements and guidance addressed to financial entities on dealing with the impact of the coronavirus (COVID-19) outbreak.

    March 26, 2020 WebPage Regulatory News
    News

    ISDA and Industry Request Delay in Timeline for Initial Margin Rules

    Considering the challenges posed by the COVID-19 pandemic, ISDA submitted a letter on behalf of 21 industry associations and their members requesting BCBS, IOSCO, and global regulators to suspend the current timeline for the initial margin phase-in.

    March 26, 2020 WebPage Regulatory News
    News

    FCA, FRC, and PRA Issue Joint Statement to Address Impact of COVID-19

    In response to the COVID-19 outbreak, FCA, the Financial Reporting Council (FRC), and PRA have announced a series of actions and made statements to support the continued functioning of capital markets in the UK.

    March 26, 2020 WebPage Regulatory News
    News

    EC Rule Corrects Regulation Supplementing Solvency II Directive

    EC published the EU Delegated Regulation 2020/442, which corrects the EU Delegated Regulation 2015/35 that supplements Solvency II Directive (2009/138/EC).

    March 26, 2020 WebPage Regulatory News
    News

    FED and FFIEC Offer Reporting Relief to Institutions Due to COVID-19

    FED and FFIEC announced regulatory reporting relief to financial institutions due to disruptions caused by the COVID-19.

    March 26, 2020 WebPage Regulatory News
    RESULTS 1 - 10 OF 4900